CVE-2024-10573 Information
Description
An out-of-bounds write flaw was found in mpg123 when handling crafted streams. When decoding PCM the libmpg123 may write past the end of a heap-located buffer. Consequently heap corruption may happen and arbitrary code execution is not discarded. The complexity required to exploit this flaw is considered high as the payload must be validated by the MPEG decoder and the PCM synth before execution. Additionally to successfully execute the attack the user must scan through the stream making web live stream content (such as web radios) a very unlikely attack vector.
CVSS Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Reference
https://access.redhat.com/security/cve/CVE-2024-10573 https://bugzilla.redhat.com/show_bug.cgi?id=2322980 https://mpg123.org/cgi-bin/news.cgi#2024-10-26
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction Required
LOW
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
6.7
Share on: