From $URL: "as upstream of mpg123, I recently fixed a possibly serious issue that resulted in writing past a buffer on the heap under certain use cases. The fixed release is 1.32.8. There is no CVE for this (that I know of)." They go on to explain the circumstances needed to hit the bug - seeking around in a malicious stream - and consider it non trivial to exploit. For example, as I read it, just playing a malicious crafted .mp3 will not do it. 1.32.8, released a few days ago, includes fixes.
I'll go with Denial of Service given the difficulty to exploit.