Out-of-bounds write in mpg123 - CVE-2024-10573
Published: November 12, 2024
Vulnerability identifier: #VU100239
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-10573
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error within libmpg123 when decoding PCM. A remote attacker can pass specially crafted data to the application, trigger an out-of-bounds write leading to a heap corruption and execute arbitrary code on the system.
Affected software
mpg123
Debian Linux
Red Hat CodeReady Linux Builder for x86_64
Anolis OS
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Ubuntu
Fedora
mpg123 (Ubuntu package)
libmpg123-0 (Ubuntu package)
mpg123 (Debian package)
libmpg123-0t64 (Ubuntu package)
mpg123-plugins-pulseaudio
mpg123
mpg123-devel
mpg123-libs
mpg123 (Red Hat package)
wine-mono
wine
Debian Linux
Red Hat CodeReady Linux Builder for x86_64
Anolis OS
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Ubuntu
Fedora
mpg123 (Ubuntu package)
libmpg123-0 (Ubuntu package)
mpg123 (Debian package)
libmpg123-0t64 (Ubuntu package)
mpg123-plugins-pulseaudio
mpg123
mpg123-devel
mpg123-libs
mpg123 (Red Hat package)
wine-mono
wine
How to mitigate CVE-2024-10573
Install updates from vendor's website.
mpg123 - update to 1.32.8
mpg123 (Ubuntu package) - addressed in versions 1.25.13-1ubuntu0.1, 1.25.13-1ubuntu0.2, 1.29.3-1ubuntu0.1, 1.32.5-1ubuntu1.1, 1.32.7-1ubuntu0.1
libmpg123-0 (Ubuntu package) - addressed in versions 1.25.13-1ubuntu0.1, 1.25.13-1ubuntu0.2, 1.29.3-1ubuntu0.1
mpg123 (Debian package) - update to 1.31.2-1+deb12u1
libmpg123-0t64 (Ubuntu package) - addressed in versions 1.32.5-1ubuntu1.1, 1.32.7-1ubuntu0.1
mpg123-plugins-pulseaudio - update to 1.32.9-1
mpg123 - update to 1.32.9-1
mpg123-devel - update to 1.32.9-1
mpg123-libs - update to 1.32.9-1
mpg123 (Red Hat package) - addressed in versions 1.32.9-1.el8_10, 1.32.9-1.el9_5
wine-mono - update to 10.1.0-1.fc41
wine - update to 10.12-2.fc41
mpg123 (Ubuntu package) - addressed in versions 1.25.13-1ubuntu0.1, 1.25.13-1ubuntu0.2, 1.29.3-1ubuntu0.1, 1.32.5-1ubuntu1.1, 1.32.7-1ubuntu0.1
libmpg123-0 (Ubuntu package) - addressed in versions 1.25.13-1ubuntu0.1, 1.25.13-1ubuntu0.2, 1.29.3-1ubuntu0.1
mpg123 (Debian package) - update to 1.31.2-1+deb12u1
libmpg123-0t64 (Ubuntu package) - addressed in versions 1.32.5-1ubuntu1.1, 1.32.7-1ubuntu0.1
mpg123-plugins-pulseaudio - update to 1.32.9-1
mpg123 - update to 1.32.9-1
mpg123-devel - update to 1.32.9-1
mpg123-libs - update to 1.32.9-1
mpg123 (Red Hat package) - addressed in versions 1.32.9-1.el8_10, 1.32.9-1.el9_5
wine-mono - update to 10.1.0-1.fc41
wine - update to 10.12-2.fc41
External References
Related Security Bulletins
- Remote code execution in mpg123 library
- Debian update for mpg123
- Ubuntu update for mpg123
- Ubuntu update for mpg123
- Red Hat Enterprise Linux 8 update for mpg123
- Red Hat Enterprise Linux 9 update for the mpg123:1.32.9 module
- Anolis OS update for mpg123
- Anolis OS update for mpg123
- Fedora 41 update for wine, wine-mono