Bug 32479 - vorbis-tools new security issue CVE-2023-43361
Summary: vorbis-tools new security issue CVE-2023-43361
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8TOO MGA8-64-OK MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2023-11-02 15:25 CET by Nicolas Salguero
Modified: 2023-11-12 02:46 CET (History)
7 users (show)

See Also:
Source RPM: vorbis-tools-1.4.2-3.mga9.src.rpm
CVE:
Status comment: Patches available from openSUSE


Attachments

Description Nicolas Salguero 2023-11-02 15:25:26 CET
Hi,

CVE-2023-43361 was announced here:
https://lwn.net/Articles/949233/

Mageia 8 and 9 are also affected.

Best regards,

Nico.
Nicolas Salguero 2023-11-02 15:26:00 CET

Source RPM: (none) => vorbis-tools-1.4.2-3.mga9.src.rpm
Whiteboard: (none) => MGA9TOO, MGA8TOO
CC: (none) => nicolas.salguero

Nicolas Salguero 2023-11-02 15:26:17 CET

Status comment: (none) => Patches available from openSUSE

Comment 1 Lewis Smith 2023-11-02 18:37:09 CET
Suse 'Fixed package version(s)' cite v1.4.0; perhaps our 1.4.2 is already OK.

Assigning globally, no evident packager for this.

Assignee: bugsquad => pkg-bugs

Comment 2 David GEIGER 2023-11-03 07:12:22 CET
Assigning to QA,

Packages in 9/Core/Updates_testing:
======================
vorbis-tools-1.4.2-3.1.mga9

Packages in 8/Core/Updates_testing:
======================
vorbis-tools-1.4.0-15.1.mga8


From SRPMS:
vorbis-tools-1.4.2-3.1.mga9.src.rpm
vorbis-tools-1.4.0-15.1.mga8.src.rpm

Whiteboard: MGA9TOO, MGA8TOO => MGA8TOO
Assignee: pkg-bugs => qa-bugs
CC: (none) => geiger.david68210
Version: Cauldron => 9

PC LX 2023-11-03 09:19:05 CET

CC: (none) => mageia

Comment 3 Marja Van Waes 2023-11-03 10:14:42 CET
Advisory based on comment 2 and the changelog mail added to SVN. Please remove the "advisory" keyword if it needs to be changed. It also helps when obsolete advisories are tagged as "obsolete"

CC: (none) => marja11
Keywords: (none) => advisory

Comment 4 Herman Viaene 2023-11-06 17:18:27 CET
MGA8-64 Xfce on Acer Aspire 5253
No installation issues
Ref bug 16677 for testing.
$ ogg123 01Blauwe\ geschelptesnel.ogg 

Audio Device:   PulseAudio Output

Playing: 01Blauwe geschelptesnel.ogg
Ogg Vorbis stream: 2 channel, 44100 Hz
                                                                                
Done.
plays OK

$ oggenc -L blauw.txt 01Blauwe\ geschelpte.wav 
WARNING: Kate support not compiled in; lyrics will not be included.
Skipping chunk of type "LIST", length 52
Opening with wav module: WAV file reader
Encoding "01Blauwe geschelpte.wav" to 
         "01Blauwe geschelpte.ogg" 
at quality 3.00
	[ 99.6%] [ 0m00s remaining] / 

Done encoding file "01Blauwe geschelpte.ogg"

	File length:  3m 34.0s
	Elapsed time: 0m 21.6s
	Rate:         9.9147
	Average bitrate: 117.0 kb/s
The "Skipping chunk of type "LIST", length 52" which seems to refer to the text file lets me suppose that this file is not processed (see further below)
$ ogg123 01Blauwe\ geschelpte.ogg

Audio Device:   PulseAudio Output

Playing: 01Blauwe geschelpte.ogg
Ogg Vorbis stream: 2 channel, 44100 Hz
                                                                                
Done.
File plays OK.

$ oggdec 01Blauwe\ geschelptesnel.ogg 
oggdec from vorbis-tools 1.4.0
Decoding "01Blauwe geschelptesnel.ogg" to "01Blauwe geschelptesnel.wav"
	[100.0%]
File plays OK
[tester8@mach7 Music]$ ogginfo 01Blauwe\ geschelptesnel.ogg
Processing file "01Blauwe geschelptesnel.ogg"...

New logical stream (#1, serial: 07895ce1): type vorbis
Vorbis headers parsed for stream 1, information follows...
Version: 0
Vendor: Xiph.Org libVorbis I 20200704 (Reducing Environment)
Channels: 2
Rate: 44100

Nominal bitrate: 499.821000 kb/s
Upper bitrate not set
Lower bitrate not set
Vorbis stream 1:
	Total data length: 3687608 bytes
	Playback length: 1m:04.344s
	Average bitrate: 458.486537 kb/s
Logical stream 1 ended

$ vcut 01Blauwe\ geschelpte.ogg blauw1.ogg blauw2.ogg +60
Processing: Cutting at 60.000000 seconds
Segmentation fault (core dumped)
This is the same as with the previous vorbis-tools-1.4.0-15.mga8 package, so no regression

$ vorbiscomment 01Blauwe\ geschelpte.ogg
No comment displayed which is consistent with the message frop the oggenc command above.
Good to go.

CC: (none) => herman.viaene
Whiteboard: MGA8TOO => MGA8TOO MGA8-64-OK

Comment 5 Herman Viaene 2023-11-10 13:05:15 CET
MGA9-64 Xfce on Acer Aspire 5253
No installation issues.
Using the same files as above Comment 4, getting exact the same results, with the exception that the vcut command ends OK (no feedback) and generates two expected files, which play Ok with parole.
Good to go for me.

Whiteboard: MGA8TOO MGA8-64-OK => MGA8TOO MGA8-64-OK MGA9-64-OK

Comment 6 Thomas Andrews 2023-11-10 15:03:29 CET
Validating.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Comment 7 Mageia Robot 2023-11-12 02:46:49 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2023-0316.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.