{"id":"UBUNTU-CVE-2023-49356","details":"A stack buffer overflow vulnerability in MP3Gain v1.6.2 allows an attacker to cause a denial of service via the WriteMP3GainAPETag function at apetag.c:592.","modified":"2025-07-16T07:20:49.448570Z","published":"2023-12-22T10:15:00Z","withdrawn":"2025-07-18T16:54:42Z","upstream":["CVE-2023-49356"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-49356"},{"type":"REPORT","url":"https://github.com/linzc21/bug-reports/blob/main/reports/mp3gain/1.6.2/stack-buffer-overflow/CVE-2023-49356.md"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2023-49356"}],"affected":[{"package":{"name":"mp3gain","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/mp3gain@1.6.2-2?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6.2-2"}]}],"ecosystem_specific":{"binaries":[{"binary_name":"mp3gain","binary_version":"1.6.2-2"},{"binary_version":"1.6.2-2","binary_name":"mp3gain-dbgsym"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-49356.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]}