Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Mageia 9: MGASA-2024-0358 High: mpg123 out-of-bounds execution risk

mageia
Calendar Grey November 12, 2024
Dist Mageia Esm H88
MGASA-2024-0457 upgrades ffmpeg packages to address a critical security vulnerability that may result in unauthorized access.
An out-of-bounds write flaw was found in mpg123 when handling crafted streams

Summary

An out-of-bounds write flaw was found in mpg123 when handling crafted streams. When decoding PCM, the libmpg123 may write past the end of a heap-located buffer. Consequently, heap corruption may happen, and arbitrary code execution may not be dismissed. The complexity required to exploit this flaw is considered high as the payload must be validated by the MPEG decoder and the PCM synth before execution. Additionally, to successfully execute the attack, the user must scan through the stream, making web live stream content (such as web radios) a very unlikely attack vector. (CVE-2024-10573)

References

- https://bugs.mageia.org/show_bug.cgi?id=33711

- https://www.openwall.com/lists/oss-security/2024/10/30/2

- https://www.openwall.com/lists/oss-security/2024/10/30/3

- https://www.openwall.com/lists/oss-security/2024/10/31/4

- https://www.openwall.com/lists/oss-security/2024/11/01/2

- https://www.cve.org/CVERecord?id=CVE-2024-10573

Resolution

SRPMS

- 9/core/mpg123-1.31.3-1.1.mga9

Publication date: 12 Nov 2024
URL: https://advisories.mageia.org/MGASA-2024-0358.html
Type: security
CVE: CVE-2024-10573

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here