ALSA-2024:11193

Source
https://errata.almalinux.org/8/ALSA-2024-11193.html
Import Source
https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2024:11193.json
JSON Data
https://api.osv.dev/v1/vulns/ALSA-2024:11193
Related
Published
2024-12-17T00:00:00Z
Modified
2024-12-18T12:42:45Z
Summary
Moderate: mpg123 security update
Details

The mpg123 packages contain real time MPEG 1.0/2.0/2.5 audio player/decoder for layers 1, 2, and 3 (most commonly MPEG 1.0 layer 3 also known as MP3), as well as re-usable decoding and output libraries.

Security Fix(es):

  • mpg123: Buffer overflow when writing decoded PCM samples (CVE-2024-10573)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References

Affected packages

AlmaLinux:8 / mpg123

Package

Name
mpg123
Purl
pkg:rpm/almalinux/mpg123

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.32.9-1.el8_10

AlmaLinux:8 / mpg123-devel

Package

Name
mpg123-devel
Purl
pkg:rpm/almalinux/mpg123-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.32.9-1.el8_10

AlmaLinux:8 / mpg123-libs

Package

Name
mpg123-libs
Purl
pkg:rpm/almalinux/mpg123-libs

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.32.9-1.el8_10

AlmaLinux:8 / mpg123-plugins-pulseaudio

Package

Name
mpg123-plugins-pulseaudio
Purl
pkg:rpm/almalinux/mpg123-plugins-pulseaudio

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.32.9-1.el8_10