[ GLSA 202107-46 ] mpv: Format string vulnerability

John Helmert III <[email protected]>
Newsgroups gmane.linux.gentoo.announce
Message-ID <[email protected]>
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 202107-46
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                           https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

 Severity: Normal
    Title: mpv: Format string vulnerability
     Date: July 20, 2021
     Bugs: #780474
       ID: 202107-46

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

A format string vulnerability was found in mpv, potentially resulting
in arbitrary code execution.

Background
==========

Video player based on MPlayer/mplayer2.

Affected packages
=================

    -------------------------------------------------------------------
     Package              /     Vulnerable     /            Unaffected
    -------------------------------------------------------------------
  1  media-video/mpv              < 0.33.1                  >= 0.33.1 

Description
===========

mpv uses untrusted input within format strings.

Impact
======

A remote attacker could entice a user to open a specially crafted m3u
playlist file using mpv, possibly resulting in execution of arbitrary
code with the privileges of the process or a Denial of Service
condition.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All mpv users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot --verbose ">=media-video/mpv-0.33.1"

References
==========

[ 1 ] CVE-2021-30145
      https://nvd.nist.gov/vuln/detail/CVE-2021-30145

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

 https://security.gentoo.org/glsa/202107-46

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
[email protected] or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2021 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

https://creativecommons.org/licenses/by-sa/2.5
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAABCAAdFiEElFuPenBj6NvNLoABXP0dAeB+IzgFAmD2TnIACgkQXP0dAeB+
IziMqg/9GxNCvpDNBSMHx9Evrdc9zLjLr+pPYxw22D/zy1xHKBSk02rLlAbrBWyR
heIWbdmI7hdMK3vcuOawT9PXPP2wXho4xYO8WIKBGAMkSMGp0XmkGYn28Ca3hCbz
w2cBOvz0C3kjauGhC84JheVv6//fP4C46X2fopI2NmuSfsuzSnx+U4VRbB0iC8tL
YykMzXEFVT+a5fWseovGhfv0eXt/4HRqKIsX5ZJLI2svELVhCIV3miYP3Ivud30Y
3WgLd4AOE54E7C1BC89Tx3tSUBUOJ8tpQtEjzTBjmMGI20FVTlsvfut6pQjFRu33
Qh7+1i4k5GECgpzsYQ/F2VPYedHf8X49ilYkw1u92r/D0T04JNoeYrv7nt5rbVoO
OYDVZyVanVPPOKpE6UfUACm/o7A/U22TUC6MLCf4cYVWeL44IqO+6DBrTdI3YFnC
XaQJBF11dCVCrGlajcauLo9Vm2sN8Eoa9iB53OycMAjlN/j4b0BwfhLj97TTvH99
q9iD3KJWHJdqw8xBIEHx6eKvZwie4rncWSlgW+dKFGldatgtlZUAUwMZeKfzOa/a
wyGwa8t9rmvfUfN2G5X10B9JzchM6hKMLsLHe4tcB7qTAVLacOQ5UskwoQQS3bs4
zEOuqCeG19bFDchkQH2e3Nx3hb5jC/iSnIf7TYIBq7lV7MY/hXw=
=2b6R
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.