Re: obs 30.2.0 or later: double-free on exit

Đoàn Trần Công Danh <[email protected]> Tue, 30 Jul 2024 15:32:57 +0700
Newsgroups dev.linux.lists.distributions
Message-ID <[email protected]>
On 2024-07-26 10:41:21-0700, Alan Coopersmith <[email protected]> wrote:
> On 7/26/24 01:28, Đoàn Trần Công Danh wrote:
> > I'm not sure if this mail should be sent to distros@
> > If yes, please help me forward it!
> 
> If you mean [email protected], then no, this mail should not be sent
> there.   That mailing list is only for non-public, temporarily-embargoed
> security information to be shared a short time before it goes public.

Understood!

> But since I'm not familiar with obs-studio, I don't know if there's any
> actual security exposure here to make it on-topic for the oss-security
> mailing list.  While you've described a bug that can crash the program,
> what can an attacker do to exploit it?  What will the attacker be able
> to do that they couldn't already do?

The double-free also happens with built-in plugins, (IOW, the plugins
that must be shipped together with obs-studio).  Hence, the
double-free will happens with all installation of obs-studio.

The obs-studio is used to process and broadcast audio files, which
could be used as an attack vector, I think.

-- 
Danh