Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 76862 - media-sound/mpg123: CAN-2004-0991
Summary: media-sound/mpg123: CAN-2004-0991
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All All
: High normal (vote)
Assignee: Gentoo Security
Whiteboard: B2 [glsa]
Depends on:
Reported: 2005-01-06 01:38 UTC by Jeremy Huddleston (RETIRED)
Modified: 2005-01-10 11:42 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Note You need to log in before you can comment on or make changes to this bug.
Description Jeremy Huddleston (RETIRED) gentoo-dev 2005-01-06 01:38:39 UTC
Daniel Kobras over at Debian passed this on to me.  It's fixed in mpg123-0.59s-r9.  Archs please mark stable.

Moi Jeremy!

I'm the Debian maintainer of mpg123. Recently, we got notified by a user
about (yet another) security problem with layer 2 streams. In a
nutshell, certain parameters in the MPEG header are assumed to be
constant throughout the whole stream, while different, but related
parameters are allowed to vary. This can definitely be abused to read
from illegal positions in memory and crash the app. With a few
indirections, it might even be possible to obtain a heap overflow
situation similar to CAN-2004-0805. Anyway, severity seems rather low,
but we decided to treat this as a security issue. Our security team has
assigned CAN-2004-0991 for it. The bug was discovered and investigated
by Yuri D'Elia. I've coded the attached fix for 0.59r and thought I pass
it on to you, even if it doesn't apply cleanly to Gentoo's pre-0.59s.
Looks like the header decoding has been cleaned up a bit in between, but
the bug might still be present. If you need more information about the
issue, please let me know, and I'll try to dig out some.


Comment 1 Michael Hanselmann (hansmi) (RETIRED) gentoo-dev 2005-01-06 03:08:44 UTC
Stable on ppc.
Comment 2 Jeremy Huddleston (RETIRED) gentoo-dev 2005-01-07 00:54:45 UTC
marked stable ppc64 for corsair.
Comment 3 Tim Yamin (RETIRED) gentoo-dev 2005-01-07 15:40:40 UTC
Groovy IA64 magic done; removing from CC.
Comment 4 Guy Martin (RETIRED) gentoo-dev 2005-01-08 09:26:35 UTC
Stable on hppa.
Comment 5 Bryan Østergaard (RETIRED) gentoo-dev 2005-01-08 11:39:48 UTC
Stable on alpha.
Comment 6 Hardave Riar (RETIRED) gentoo-dev 2005-01-10 06:31:09 UTC
Stable on mips.
Comment 7 Dan Margolis (RETIRED) gentoo-dev 2005-01-10 11:42:06 UTC
GLSA 200501-14