Description
A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulnerability occurs in the remote control functionality when processing malformed input, leading to a stack buffer underflow that can cause application crashes and potentially allow code execution.
References
gitlab.xiph.org/xiph/vorbis-tools/-/work_items/2332
github.com/...3897d32f4a75baa2dc915a4ca45e8e/ogg123/remote.c
github.com/xiph/vorbis-tools/archive/refs/tags/v1.4.3.tar.gz
gitlab.xiph.org/xiph/vorbis-tools/-/work_items/2332