[Pkg-alsa-devel] Bug#473384: libasound2: mpg123-alsa sometimes starts playing too fast and then crashes

Debian BTS debbugs at rietz.debian.org
Sun Mar 30 10:18:04 UTC 2008


issue
Reply-To: "Aleksej R. Serdyukov" <deletesoftware at yandex.ru>, 473384 at bugs.debian.org
Resent-From: "Aleksej R. Serdyukov" <deletesoftware at yandex.ru>
Resent-To: debian-bugs-dist at lists.debian.org
Resent-CC: Debian Security Team <team at security.debian.org>, Debian ALSA Maintainers <pkg-alsa-devel at lists.alioth.debian.org>
Resent-Date: Sun, 30 Mar 2008 10:18:01 +0000
Resent-Message-ID: <handler.473384.B.12068719019224 at bugs.debian.org>
Resent-Sender: owner at bugs.debian.org
X-Debian-PR-Message: report 473384
X-Debian-PR-Package: libasound2
X-Debian-PR-Keywords: security
X-Debian-PR-Source: alsa-lib
Received: via spool by submit at bugs.debian.org id=B.12068719019224
          (code B ref -1); Sun, 30 Mar 2008 10:18:01 +0000
Received: (at submit) by bugs.debian.org; 30 Mar 2008 10:11:41 +0000
X-Spam-Checker-Version: SpamAssassin 3.1.4-bugs.debian.org_2005_01_02 
	(2006-07-26) on rietz.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-7.7 required=4.0 tests=BAYES_00,FOURLA,HAS_PACKAGE,
	IMPRONONCABLE_2,SUBJECT_ENCODED_TWICE,SUBJECT_EXCESS_QP,URIBL_CNKR,
	X_DEBBUGS_CC autolearn=no version=3.1.4-bugs.debian.org_2005_01_02
Received: from smtp8.yandex.ru ([213.180.200.213])
	by rietz.debian.org with esmtp (Exim 4.63)
	(envelope-from <deletesoftware at yandex.ru>)
	id 1JfuVp-0002MB-E5
	for submit at bugs.debian.org; Sun, 30 Mar 2008 10:11:41 +0000
Received: from 93-80-80-59.broadband.corbina.ru ([93.80.80.59]:11945 "ehlo
        [127.0.0.1]" smtp-auth: "deletesoftware" TLS-CIPHER: <none>
        TLS-PEER-CN1: <none>) by mail.yandex.ru with ESMTP id S7458752AbYC3KLa convert rfc822-to-quoted-printable
        (ORCPT <rfc822;submit at bugs.debian.org>);
        Sun, 30 Mar 2008 14:11:30 +0400
X-Yandex-Spam: 1 
X-Yandex-Front: smtp8
X-Yandex-TimeMark: 1206871890
X-MsgDayCount: 2
X-Comment: RFC 2476 MSA function at smtp8.yandex.ru logged sender identity as: deletesoftware
MIME-Version: 1.0
Content-Transfer-Encoding: QUOTED-PRINTABLE
Content-Type:   text/plain; charset=UTF-8
From:   "Aleksej R. Serdyukov" <deletesoftware at yandex.ru>
To:     Debian Bug Tracking System <submit at bugs.debian.org>
Message-ID: <20080330101117.11954.51406.reportbug at localhost>
X-Mailer: reportbug 3.39
Date:   Sun, 30 Mar 2008 14:11:17 +0400
Delivered-To: submit at bugs.debian.org

Package: libasound2
Version: 1.0.16-2
Severity: grave
Tags: security
Justification: renders package unusable occasionally, may be a security


When playing an MP3 playlist, mpg123 v0.67-1 sometimes starts playing t=
oo fast
(no sign of words can be heard), and, after many files, resumes with
the normal speed or crashes. I believe it may be a security hole.

The music is MP3s published at vinilkosmo.com and
http://www.musicexpress.com.br/Stilo.asp?Stilo=3D36 ; I can attach the
output from the last time =E2=80=94 the shuffled playlist and file info=
 =E2=80=94 though
the times shown don=E2=80=99t seem wrong to me, and I don=E2=80=99t rem=
ember what song
was playing right before it happened.

The crash log with the last file info:

=3D=3D=3D=3D=3D
Directory: ./vinilkosmo.com/demos/el la =C4=88efpa=C4=9Do/
Playing MPEG stream 53 of 97: vkkd6201.mp3 ...
Note: Xing/Lame/Info header detected
MPEG 2.0, Layer: III, Freq: 22050, mode: Joint-Stereo, modext: 2, BPF :
208
Channels: 2, copyright: No, original: Yes, CRC: No, emphasis: 0.
Bitrate: 64 kbits/s Extension value: 0
Note: audio output rate =3D 22050
*** glibc detected *** mpg123: free(): invalid pointer: 0x08115950 ***
=3D=3D=3D=3D=3D=3D=3D Backtrace: =3D=3D=3D=3D=3D=3D=3D=3D=3D
/lib/i686/cmov/libc.so.6[0xb7d40915]
/lib/i686/cmov/libc.so.6(cfree+0x90)[0xb7d44380]
/usr/lib/libasound.so.2[0xb7eaa6d0]
/usr/lib/libasound.so.2(snd_pcm_hw_free+0x4c)[0xb7e9442c]
/usr/lib/libasound.so.2[0xb7eaf76d]
/usr/lib/libasound.so.2(snd_pcm_hw_free+0x4c)[0xb7e9442c]
/usr/lib/libasound.so.2(snd_pcm_close+0xad)[0xb7e944fd]
mpg123[0x80692a4]
=3D=3D=3D=3D=3D=3D=3D Memory map: =3D=3D=3D=3D=3D=3D=3D=3D
08048000-0807e000 r-xp 00000000 03:0b 244634     /usr/bin/mpg123-alsa
0807e000-080c3000 rwxp 00036000 03:0b 244634     /usr/bin/mpg123-alsa
080c3000-0813a000 rwxp 080c3000 00:00 0          [heap]
b7b00000-b7b21000 rwxp b7b00000 00:00 0=20
b7b21000-b7c00000 ---p b7b21000 00:00 0=20
b7c33000-b7c3f000 r-xp 00000000 03:09 302798     /lib/libgcc_s.so.1
b7c3f000-b7c40000 rwxp 0000b000 03:09 302798     /lib/libgcc_s.so.1
b7c58000-b7c78000 rwxs 00000000 00:09 4259856    /SYSV0056a4d6 (deleted=
)
b7c78000-b7c81000 r-xp 00000000 03:09 302956
/lib/i686/cmov/libnss_files-2.7.so
b7c81000-b7c83000 rwxp 00008000 03:09 302956
/lib/i686/cmov/libnss_files-2.7.so
b7c83000-b7c8b000 r-xp 00000000 03:09 302958
/lib/i686/cmov/libnss_nis-2.7.so
b7c8b000-b7c8d000 rwxp 00007000 03:09 302958
/lib/i686/cmov/libnss_nis-2.7.so
b7c8d000-b7ca1000 r-xp 00000000 03:09 302953
/lib/i686/cmov/libnsl-2.7.so
b7ca1000-b7ca3000 rwxp 00013000 03:09 302953
/lib/i686/cmov/libnsl-2.7.so
b7ca3000-b7ca5000 rwxp b7ca3000 00:00 0=20
b7ca5000-b7cac000 r-xp 00000000 03:09 302954
/lib/i686/cmov/libnss_compat-2.7.so
b7cac000-b7cae000 rwxp 00006000 03:09 302954
/lib/i686/cmov/libnss_compat-2.7.so
b7cae000-b7cb0000 rwxp b7cae000 00:00 0=20
b7cb0000-b7cb7000 r-xp 00000000 03:09 302966
/lib/i686/cmov/librt-2.7.so
b7cb7000-b7cb9000 rwxp 00006000 03:09 302966
/lib/i686/cmov/librt-2.7.so
b7cb9000-b7ccd000 r-xp 00000000 03:09 302964
/lib/i686/cmov/libpthread-2.7.so
b7ccd000-b7ccf000 rwxp 00013000 03:09 302964
/lib/i686/cmov/libpthread-2.7.so
b7ccf000-b7cd1000 rwxp b7ccf000 00:00 0=20
b7cd1000-b7cd3000 r-xp 00000000 03:09 302950
/lib/i686/cmov/libdl-2.7.so
b7cd3000-b7cd5000 rwxp 00001000 03:09 302950
/lib/i686/cmov/libdl-2.7.so
b7cd5000-b7e1c000 r-xp 00000000 03:09 302947
/lib/i686/cmov/libc-2.7.so
b7e1c000-b7e1d000 r-xp 00147000 03:09 302947
/lib/i686/cmov/libc-2.7.so
b7e1d000-b7e1f000 rwxp 00148000 03:09 302947
/lib/i686/cmov/libc-2.7.so
b7e1f000-b7e23000 rwxp b7e1f000 00:00 0=20
b7e23000-b7e46000 r-xp 00000000 03:09 302951
/lib/i686/cmov/libm-2.7.so
b7e46000-b7e48000 rwxp 00023000 03:09 302951
/lib/i686/cmov/libm-2.7.so
b7e48000-b7f05000 r-xp 00000000 03:0b 325903
/usr/lib/libasound.so.2.0.0
b7f05000-b7f0a000 rwxp 000bc000 03:0b 325903
/usr/lib/libasound.so.2.0.0
b7f0b000-b7f0e000 r-xp 00000000 03:0b 375322
/usr/lib/alsa-lib/libasound_module_rate_speexrate.so
b7f0e000-b7f0f000 rwxp 00003000 03:0b 375322
/usr/lib/alsa-lib/libasound_module_rate_speexrate.so
b7f0f000-b7f1f000 rwxs 00000000 00:0d 7203       /dev/snd/pcmC0D0p
b7f1f000-b7f20000 rwxs 81000000 00:0d 7203       /dev/snd/pcmC0D0p
b7f20000-b7f21000 r-xs 80000000 00:0d 7203       /dev/snd/pcmC0D0p
b7f21000-b7f22000 rwxs 00000000 00:09 4227084    /SYSV0056a4d5 (deleted=
)
b7f22000-b7f24000 rwxp b7f22000 00:00 0=20
b7f24000-b7f40000 r-xp 00000000 03:09 302806     /lib/ld-2.7.so
b7f40000-b7f42000 rwxp 0001b000 03:09 302806     /lib/ld-2.7.so
bf9de000-bf9f3000 rwxp bf9de000 00:00 0          [stack]
ffffe000-fffff000 r-xp 00000000 00:00 0          [vdso]
=2E./play.sh: line 2: 10569 Aborted                 mpg123 -vvv -z
- at shuffled
=3D=3D=3D=3D=3D=3D=3D

-- System Information:
Debian Release: lenny/sid
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: i386 (i686)

Kernel: Linux 2.6.22-3-k7 (SMP w/1 CPU core)
Locale: LANG=3Deo.UTF-8, LC_CTYPE=3Deo.UTF-8 (charmap=3DUTF-8)
Shell: /bin/sh linked to /bin/bash

Versions of packages libasound2 depends on:
ii  libc6                         2.7-6      GNU C Library: Shared libr=
aries

libasound2 recommends no packages.

-- no debconf information





More information about the Pkg-alsa-devel mailing list