CVE-2024-10573: Mpg123: buffer overflow when writing decoded pcm samples

Published Oct 31, 2024
·
Updated

An out-of-bounds write flaw was found in mpg123 when handling crafted streams. When decoding PCM, the libmpg123 may write past the end of a heap-located buffer. Consequently, heap corruption may happen, and arbitrary code execution is not discarded. The complexity required to exploit this flaw is considered high as the payload must be validated by the MPEG decoder and the PCM synth before execution. Additionally, to successfully execute the attack, the user must scan through the stream, making web live stream content (such as web radios) a very unlikely attack vector.

Other sources

There's a out-of-bounds write issue in mpg123, the vulnerability is located when handling crafted streams. During the decoding of PCM the libmpg123 may write past the end of a heap located buffer, as consequence heap corruption may happen and arbitrary code execution is not discarded. The complexity required to exploit this flaw is considered high as the payload needs to be validated by the MPEG decoder and by the PCM synth before being executed. Additionally to successfully execute the attack,the user needs to scan through the stream making web live stream content (such as web radios) a very unlikely attack vector.

Red Hat

This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.

Launchpad

Affected Software

1 affected componentFixes available
debian/mpg123<=1.26.4-1
1.26.4-1+deb11u11.31.2-1+deb12u11.32.10-1

Event History

Oct 31, 2024
Data Sourced
via Red Hat·05:20 PM
DescriptionSeverityAffected Software
CVE Published
via MITRE·06:31 PM
Data Sourced
via MITRE·06:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness
Nov 27, 2024
Data Sourced
via Ubuntu·04:23 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·04:24 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2024-10573?

CVE-2024-10573 is classified as a high severity vulnerability due to its potential for arbitrary code execution.

2

How do I fix CVE-2024-10573?

To fix CVE-2024-10573, update mpg123 to versions 1.26.4-1+deb11u1, 1.31.2-1+deb12u1, or 1.32.10-1.

3

Which software is affected by CVE-2024-10573?

CVE-2024-10573 affects the mpg123 package in specific Debian versions.

4

What kind of vulnerability is CVE-2024-10573?

CVE-2024-10573 is an out-of-bounds write flaw that can lead to heap corruption.

5

Can CVE-2024-10573 lead to remote code execution?

Yes, CVE-2024-10573 may allow attackers to execute arbitrary code if successfully exploited.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203