Bug#1143495: [mpg123-devel] mpg123 1.33.7 released (with lots of security fixes/improvements)
<[email protected]> Sun, 2 Aug 2026 15:39:28 -0700
| Newsgroups | gmane.linux.debian.devel.multimedia |
|---|---|
| Message-ID | <001701dd22cf$c8f88dd0$5ae9a970$__23552.6354213775$1785710849$gmane$org@synergy.org> |
Package: libmpg123-0t64 Package: libmpg123-dev Dear all, the mpg123 code to some scrutiny applied and several issues popped up. There is a mix of serious blunder and embarrasing little oversights. You really should consider updating. There is 1.34.0 in the making with = some feature changes, things waiting in the pipeline since quite some = time now, but the load of fixes demands timely release without any other = fluff. There might be CVEs. If you are stuck on something pre-1.33, you probably can prioritize some = commits or might be lucky with the diff. Lots of the bugs are in older = code.=20 Most severe is the fix for unicode path handling on Windows platforms, = and that is why I took the pain to also update the binaries via cross = build. The whole list: 1.33.7 ------ - mpg123: -- Fix heap buffer overflows in unicode path conversion on Windows (bug = 388, thanks to Alejandro Ramos). -- Fix information disclosure of uninitialied memory for --auth-file = without line endings. (bug 390, thanks to Alejandro Ramos) -- Fix out-of-bounds read/write when combining --continue --random = --listentry <n> where n is larger than the playlist size. (bug 391, thanks to = Alejandro Ramos) -- Fix a harmless valgrind memory leak report by not nulling playlist = name. -- Fix error handling of win32_net_writestring() (Windows only) by = actually using a signed type, also preventing a OOB read on failure. (bug 392 by Alejandro Ramos) -- Fix a mostly harmless OOB read of 1 byte when printing USLT lyrics. (bug 392) -- Fix leaking file descriptor on read error from --equalizer file. (bug = 392) -- Hardening of loading HTTP(S) via curl or wget against funky URLs by = including the -- separator. No actual vulnerability, tough, just extra care. = (bug 392) - out123: -- Fix heap overrun on --endian conversion with differing input and = output channel counts. (bug 391) -- Fix parsing of filter specs with whitespace before commas, which = resulted in out-of-bounds writes before. (bug 391) - libmpg123, mpg123: Harden memory realloc calls against multiplication = overflow of size_t in arguments. Specifically, this addresses part of bug 389 = with possible application abuse of mpg123_set_index64(). (bug 389 by Alejandro = Ramos) - libmpg123: -- Fix possible use of uninitialized values in layer III dequantization. III_dequantize_sample() for consistent output also for strange input. = The new code seems to be slightly faster after some rearrangements. (thanks to He Huang, Swinburne University of Technology (discovered = using NexusSan)) -- Fix a double free when deleting a handle after failed = mpg123_decoder() call (possibly among others). (bug 389) -- More strong wording in API that ID3 text convenience links are = short-lived, but safeguard against ignorant use by nulling them early. (bug 389) -- Prevent double free in mpg123_set_index() 32 bit wrapper being called = with index size 0. (bug 392) -- Harden against an application wielding a foot gun by handing in an = undersized decoding buffer betwee seek and read (return error before trying to = decode and discard frames in that case). (bug 392) -- Do properly terminate ID3v2 texts coming in UTF16 encoding when they = overwrite previous frames, like with other encodings. The symptom was a shorter = second frame resulting in a combined text with the earlier longer frame. (bug 392) -- Check and properly handle null source buffer and zero size in = mpg123_store_utf8() instead of reading past (before) buffers. (bug 392) -- Ensure clients get ID3v1 data with (unmotivated) mpg123_id3_raw() only if the parser decided that it is there, not possibly the last = 128 bytes of a seekable stream without ID3v1 tag. (bug 392) -- Prevent impossible NtoM resampling with too low target rate (like 1 = Hz) which would trgger endless looping. (bug 392) - libout123: -- Fix deadlock in buffer mode when combined with (stereo) 24 bit = output. Now also mpg123 --buffer 4096 -e s24 shall actuallly work. Sorry. (bug = 392) -- Abort early on zero/negative rate and channel count in = out123_start(). (bug 392) -- Fix divide by zero in WAV writing by catching channel counts that go = zero in the 16 bit WAV header field. (bug 392) - libsyn123: -- Explictly reject mismatched format for appending filters with syn123_setup_filter(), preventing memory errors from that = API-violating use. (bug 392) -- Harden the dirty resampling interpolator against extreme rates = (around 1e18 Hz) by fixing a sample offset check to not do the exact overflowing = addition that it is supposed to guard against. The fine resampler was = =E2=80=A6 fine. (bug 392) -- Error out on trying to create a filter of order 0 instead of dividing = by zero later. (bug 392) Get it while it is hot =E2=80=A6 and before the next round of bugs = discoveries arrive. Alrighty then (or not), Thomas _______________________________________________ mpg123-devel mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/mpg123-devel