Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 942561 (CVE-2024-10573) - media-sound/mpg123-base: heap overflow when seeking on a malicious stream
Summary: media-sound/mpg123-base: heap overflow when seeking on a malicious stream
Status: CONFIRMED
Alias: CVE-2024-10573
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Gentoo Security
URL: https://marc.info/?l=oss-security&m=1...
Whiteboard: A3 [ebuild]
Keywords:
Depends on:
Blocks:
 
Reported: 2024-10-30 18:28 UTC by Hank Leininger
Modified: 2024-11-12 18:50 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Hank Leininger 2024-10-30 18:28:53 UTC
From $URL:

"as upstream of mpg123, I recently fixed a possibly serious issue that
resulted in writing past a buffer on the heap under certain use cases.
The fixed release is 1.32.8. 

There is no CVE for this (that I know of)."

They go on to explain the circumstances needed to hit the bug - seeking around in a malicious stream - and consider it non trivial to exploit. For example, as I read it, just playing a malicious crafted .mp3 will not do it.

1.32.8, released a few days ago, includes fixes.
Comment 1 Hans de Graaff gentoo-dev Security 2024-11-12 18:50:21 UTC
I'll go with Denial of Service given the difficulty to exploit.