Bug#1143495: [mpg123-devel] mpg123 1.33.7 released (with lots of security fixes/improvements)

<[email protected]> Sun, 2 Aug 2026 15:39:28 -0700
Newsgroups gmane.linux.debian.devel.multimedia
Message-ID <001701dd22cf$c8f88dd0$5ae9a970$__23552.6354213775$1785710849$gmane$org@synergy.org>
Package: libmpg123-0t64
Package: libmpg123-dev

Dear all,

the mpg123 code to some scrutiny applied and several issues popped up.

There is a mix of serious blunder and embarrasing little oversights.
You really should consider updating. There is 1.34.0 in the making with =
some feature changes, things waiting in the pipeline since quite some =
time now, but the load of fixes demands timely release without any other =
fluff. There might be CVEs.

If you are stuck on something pre-1.33, you probably can prioritize some =
commits or might be lucky with the diff. Lots of the bugs are in older =
code.=20

Most severe is the fix for unicode path handling on Windows platforms, =
and that is why I took the pain to also update the binaries via cross =
build. The whole list:

1.33.7
------
- mpg123:
-- Fix heap buffer overflows in unicode path conversion on Windows (bug =
388,
   thanks to Alejandro Ramos).
-- Fix information disclosure of uninitialied memory for --auth-file =
without
   line endings. (bug 390, thanks to Alejandro Ramos)
-- Fix out-of-bounds read/write when combining --continue --random =
--listentry <n>
   where n is larger than the playlist size. (bug 391, thanks to =
Alejandro Ramos)
-- Fix a harmless valgrind memory leak report by not nulling playlist =
name.
-- Fix error handling of win32_net_writestring() (Windows only) by =
actually using
   a signed type, also preventing a OOB read on failure.
   (bug 392 by Alejandro Ramos)
-- Fix a mostly harmless OOB read of 1 byte when printing USLT lyrics.
   (bug 392)
-- Fix leaking file descriptor on read error from --equalizer file. (bug =
392)
-- Hardening of loading HTTP(S) via curl or wget against funky URLs by =
including
   the -- separator. No actual vulnerability, tough, just extra care. =
(bug 392)
- out123:
-- Fix heap overrun on --endian conversion with differing input and =
output
   channel counts. (bug 391)
-- Fix parsing of filter specs with whitespace before commas, which =
resulted
   in out-of-bounds writes before. (bug 391)
- libmpg123, mpg123: Harden memory realloc calls against multiplication =
overflow
  of size_t in arguments. Specifically, this addresses part of bug 389 =
with possible
  application abuse of mpg123_set_index64(). (bug 389 by Alejandro =
Ramos)
- libmpg123:
-- Fix possible use of uninitialized values in layer III dequantization.
   III_dequantize_sample() for consistent output also for strange input. =
The new
   code seems to be slightly faster after some rearrangements.
   (thanks to He Huang, Swinburne University of Technology (discovered =
using
   NexusSan))
-- Fix a double free when deleting a handle after failed =
mpg123_decoder() call
   (possibly among others). (bug 389)
-- More strong wording in API that ID3 text convenience links are =
short-lived,
   but safeguard against ignorant use by nulling them early.
   (bug 389)
-- Prevent double free in mpg123_set_index() 32 bit wrapper being called =
with
   index size 0. (bug 392)
-- Harden against an application wielding a foot gun by handing in an =
undersized
   decoding buffer betwee seek and read (return error before trying to =
decode
   and discard frames in that case). (bug 392)
-- Do properly terminate ID3v2 texts coming in UTF16 encoding when they =
overwrite
   previous frames, like with other encodings. The symptom was a shorter =
second
   frame resulting in a combined text with the earlier longer frame.
   (bug 392)
-- Check and properly handle null source buffer and zero size in =
mpg123_store_utf8()
   instead of reading past (before) buffers. (bug 392)
-- Ensure clients get ID3v1 data with (unmotivated) mpg123_id3_raw()
   only if the parser decided that it is there, not possibly the last =
128 bytes of
   a seekable stream without ID3v1 tag. (bug 392)
-- Prevent impossible NtoM resampling with too low target rate (like 1 =
Hz) which
   would trgger endless looping. (bug 392)
- libout123:
-- Fix deadlock in buffer mode when combined with (stereo) 24 bit =
output. Now
   also mpg123 --buffer 4096 -e s24 shall actuallly work. Sorry. (bug =
392)
-- Abort early on zero/negative rate and channel count in =
out123_start().
   (bug 392)
-- Fix divide by zero in WAV writing by catching channel counts that go =
zero in the
   16 bit WAV header field. (bug 392)
- libsyn123:
-- Explictly reject mismatched format for appending filters with
   syn123_setup_filter(), preventing memory errors from that =
API-violating use.
   (bug 392)
-- Harden the dirty resampling interpolator against extreme rates =
(around 1e18 Hz)
   by fixing a sample offset check to not do the exact overflowing =
addition
   that it is supposed to guard against. The fine resampler was =
=E2=80=A6 fine. (bug 392)
-- Error out on trying to create a filter of order 0 instead of dividing =
by zero
   later. (bug 392)

Get it while it is hot =E2=80=A6 and before the next round of bugs =
discoveries arrive.


Alrighty then (or not),

Thomas


_______________________________________________
mpg123-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mpg123-devel