Bugzilla – Bug 64776
VUL-0: CVE-2004-0982: verify mpg123 patches are sufficient
Last modified: 2021-10-19 14:04:39 UTC
gentoo uses a more complicated patch for CAN-2004-0982. Verify that 103_all_CAN-2004-0982.patch and mpg123-0.59s-http-auth-overflow.patch are the same.
Created attachment 27591 [details] 103_all_CAN-2004-0982.patch
mpg123-0.59s-http-auth-overflow.patch is not sufficient as it seems. At least the ' ' -> %20 encoding loop can still overflow.
I replaced the patch with the gentoo one. Packages with fix for 49776 and 49775 are submitted.
Do we need patchinfo files or is it a stable-only fix?
I fixed it in all releases (8.1-9.2). Yes, the patchinfo is needed.
swamp id: 209
updates released.
CVE-2004-0982: CVSS v2 Base Score: 10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C)