Bug 19610 - mpg123 new security issue CVE-2016-1000247
Summary: mpg123 new security issue CVE-2016-1000247
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 5
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL: http://lwn.net/Vulnerabilities/703771/
Whiteboard: MGA5-32-OK advisory
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2016-10-17 18:44 CEST by David Walser
Modified: 2016-10-26 01:12 CEST (History)
4 users (show)

See Also:
Source RPM: mpg123-1.20.1-4.mga5.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2016-10-17 18:44:02 CEST
Debian-LTS has issued an advisory on October 15:
http://lwn.net/Alerts/703760/

The issue is fixed upstream in 1.23.8.  Freeze push requested for Cauldron.

Upstream announcement is here:
http://www.mpg123.de/cgi-bin/news.cgi

Patch checked into Mageia 5 SVN.
Comment 1 David Walser 2016-10-17 21:18:25 CEST
Patched package uploaded for Mageia 5.

Advisory:
========================

Updated mpg123 packages fix security vulnerability:

Jerold Hoong discovered a flaw in the id3 tag processing code of libmpg123. A
specially crafted mp3 input file could be used to cause a buffer over-read,
resulting in a denial of service (CVE-2016-1000247).

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1000247
http://www.mpg123.de/cgi-bin/news.cgi
http://lwn.net/Alerts/703760/
========================

Updated packages in core/updates_testing:
========================
mpg123-1.20.1-4.1.mga5
mpg123-pulse-1.20.1-4.1.mga5
mpg123-jack-1.20.1-4.1.mga5
mpg123-portaudio-1.20.1-4.1.mga5
mpg123-sdl-1.20.1-4.1.mga5
mpg123-openal-1.20.1-4.1.mga5
libmpg123_0-1.20.1-4.1.mga5
libmpg123-devel-1.20.1-4.1.mga5

from mpg123-1.20.1-4.1.mga5.src.rpm

Assignee: bugsquad => qa-bugs

Comment 2 Herman Viaene 2016-10-20 13:43:25 CEST
MGA5-32 on Acer D620 Xfce
No installation issues
Played mp3 file with mpg123 OK

CC: (none) => herman.viaene
Whiteboard: (none) => MGA5-32-OK

Comment 3 Lewis Smith 2016-10-23 10:03:03 CEST
Advisory uploaded.

CC: (none) => lewyssmith
Whiteboard: MGA5-32-OK => MGA5-32-OK advisory

Dave Hodgins 2016-10-25 22:47:27 CEST

Keywords: (none) => validated_update
CC: (none) => davidwhodgins, sysadmin-bugs

Comment 4 Mageia Robot 2016-10-26 01:12:27 CEST
An update for this issue has been pushed to the Mageia Updates repository.

http://advisories.mageia.org/MGASA-2016-0358.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.