Format string error in mpv - CVE-2021-30145
Published: September 10, 2024
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a format string error when parsing m3u playlist files. A remote attacker can supply a specially crafted file that contains format string specifiers and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Gentoo Linux
openEuler
mpv
mpv-debuginfo
mpv-libs
mpv-libs-devel
mpv-debugsource
media-video/mpv
How to mitigate CVE-2021-30145
mpv - update to 0.32.0-3
mpv-debuginfo - update to 0.32.0-3
mpv-libs - update to 0.32.0-3
mpv-libs-devel - update to 0.32.0-3
mpv-debugsource - update to 0.32.0-3
media-video/mpv - update to 0.33.1