USN-7092-1

Source
https://ubuntu.com/security/notices/USN-7092-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7092-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-7092-1
Related
Published
2024-11-05T12:59:36.389432Z
Modified
2024-11-05T12:59:36.389432Z
Summary
mpg123 vulnerability
Details

It was discovered that mpg123 incorrectly handled certain mp3 files. If a user or automated system were tricked into opening a specially crafted mp3 file, a remote attacker could use this issue to cause mpg123 to crash, resulting in a denial of service, or possibly execute arbitrary code.

References

Affected packages

Ubuntu:20.04:LTS / mpg123

Package

Name
mpg123
Purl
pkg:deb/ubuntu/mpg123?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.25.13-1ubuntu0.1

Affected versions

1.*

1.25.12-1build1
1.25.13-1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "1.25.13-1ubuntu0.1",
            "binary_name": "libmpg123-0"
        },
        {
            "binary_version": "1.25.13-1ubuntu0.1",
            "binary_name": "libmpg123-0-dbgsym"
        },
        {
            "binary_version": "1.25.13-1ubuntu0.1",
            "binary_name": "libmpg123-dev"
        },
        {
            "binary_version": "1.25.13-1ubuntu0.1",
            "binary_name": "libout123-0"
        },
        {
            "binary_version": "1.25.13-1ubuntu0.1",
            "binary_name": "libout123-0-dbgsym"
        },
        {
            "binary_version": "1.25.13-1ubuntu0.1",
            "binary_name": "mpg123"
        },
        {
            "binary_version": "1.25.13-1ubuntu0.1",
            "binary_name": "mpg123-dbgsym"
        }
    ]
}

Ubuntu:22.04:LTS / mpg123

Package

Name
mpg123
Purl
pkg:deb/ubuntu/mpg123?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.29.3-1ubuntu0.1

Affected versions

1.*

1.28.2-2
1.29.2-1
1.29.3-1
1.29.3-1build1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "1.29.3-1ubuntu0.1",
            "binary_name": "libmpg123-0"
        },
        {
            "binary_version": "1.29.3-1ubuntu0.1",
            "binary_name": "libmpg123-0-dbgsym"
        },
        {
            "binary_version": "1.29.3-1ubuntu0.1",
            "binary_name": "libmpg123-dev"
        },
        {
            "binary_version": "1.29.3-1ubuntu0.1",
            "binary_name": "libout123-0"
        },
        {
            "binary_version": "1.29.3-1ubuntu0.1",
            "binary_name": "libout123-0-dbgsym"
        },
        {
            "binary_version": "1.29.3-1ubuntu0.1",
            "binary_name": "libsyn123-0"
        },
        {
            "binary_version": "1.29.3-1ubuntu0.1",
            "binary_name": "libsyn123-0-dbgsym"
        },
        {
            "binary_version": "1.29.3-1ubuntu0.1",
            "binary_name": "mpg123"
        },
        {
            "binary_version": "1.29.3-1ubuntu0.1",
            "binary_name": "mpg123-dbgsym"
        }
    ]
}

Ubuntu:24.10 / mpg123

Package

Name
mpg123
Purl
pkg:deb/ubuntu/mpg123?arch=src?distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.32.7-1ubuntu0.1

Affected versions

1.*

1.32.5-1ubuntu1
1.32.6-3
1.32.7-1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "1.32.7-1ubuntu0.1",
            "binary_name": "libmpg123-0t64"
        },
        {
            "binary_version": "1.32.7-1ubuntu0.1",
            "binary_name": "libmpg123-0t64-dbgsym"
        },
        {
            "binary_version": "1.32.7-1ubuntu0.1",
            "binary_name": "libmpg123-dev"
        },
        {
            "binary_version": "1.32.7-1ubuntu0.1",
            "binary_name": "libout123-0t64"
        },
        {
            "binary_version": "1.32.7-1ubuntu0.1",
            "binary_name": "libout123-0t64-dbgsym"
        },
        {
            "binary_version": "1.32.7-1ubuntu0.1",
            "binary_name": "libsyn123-0t64"
        },
        {
            "binary_version": "1.32.7-1ubuntu0.1",
            "binary_name": "libsyn123-0t64-dbgsym"
        },
        {
            "binary_version": "1.32.7-1ubuntu0.1",
            "binary_name": "mpg123"
        },
        {
            "binary_version": "1.32.7-1ubuntu0.1",
            "binary_name": "mpg123-dbgsym"
        }
    ]
}

Ubuntu:24.04:LTS / mpg123

Package

Name
mpg123
Purl
pkg:deb/ubuntu/mpg123?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.32.5-1ubuntu1.1

Affected versions

1.*

1.31.3-2
1.32.3-1
1.32.4-1
1.32.5-1
1.32.5-1build2
1.32.5-1ubuntu1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "1.32.5-1ubuntu1.1",
            "binary_name": "libmpg123-0t64"
        },
        {
            "binary_version": "1.32.5-1ubuntu1.1",
            "binary_name": "libmpg123-0t64-dbgsym"
        },
        {
            "binary_version": "1.32.5-1ubuntu1.1",
            "binary_name": "libmpg123-dev"
        },
        {
            "binary_version": "1.32.5-1ubuntu1.1",
            "binary_name": "libout123-0t64"
        },
        {
            "binary_version": "1.32.5-1ubuntu1.1",
            "binary_name": "libout123-0t64-dbgsym"
        },
        {
            "binary_version": "1.32.5-1ubuntu1.1",
            "binary_name": "libsyn123-0t64"
        },
        {
            "binary_version": "1.32.5-1ubuntu1.1",
            "binary_name": "libsyn123-0t64-dbgsym"
        },
        {
            "binary_version": "1.32.5-1ubuntu1.1",
            "binary_name": "mpg123"
        },
        {
            "binary_version": "1.32.5-1ubuntu1.1",
            "binary_name": "mpg123-dbgsym"
        }
    ]
}