[Bug 1197614] New: moc player buffer overflow detected
http://bugzilla.opensuse.org/show_bug.cgi?id=1197614 Bug ID: 1197614 Summary: moc player buffer overflow detected Classification: openSUSE Product: openSUSE Tumbleweed Version: Current Hardware: 64bit OS: openSUSE Tumbleweed Status: NEW Severity: Normal Priority: P5 - None Component: Other Assignee: screening-team-bugs@suse.de Reporter: victorhck@opensuse.org QA Contact: qa-bugs@suse.de Found By: --- Blocker: --- After run mocp command to run moc player in a terminal emulator, I get this error: *** buffer overflow detected ***: terminated I found a similar error in Arch bug history: https://bugs.archlinux.org/task/74041 More info: mocp -V This is : Music On Console Version : 2.6-alpha3 Compiled with : ALSA JACK DEBUG Network streams resample Running on : Linux 5.16.15-1-default x86_64 Author : Damian Pietras Homepage : http://moc.daper.net/ E-Mail : mocmaint@daper.net Copyright : (C) 2003-2016 Damian Pietras and others License : GNU General Public License, version 2 or later Log created with mocp: Mar 28 18:55:17.560777: main.c:1182 main(): This is Music On Console (version 2.6-alpha3) Mar 28 18:55:17.560853: main.c:1186 main(): Configured: '--host=x86_64-suse-linux-gnu' '--build=x86_64-suse-linux-gnu' '--program-prefix=' '--prefix=/usr' '--exec-prefix=/usr' '--bindir=/usr/bin' '--sbindir=/usr/sbin' '--sysconfdir=/etc' '--datadir=/usr/share' '--includedir=/usr/include' '--libdir=/usr/lib64' '--libexecdir=/usr/libexec' '--localstatedir=/var' '--sharedstatedir=/var/lib' '--mandir=/usr/share/man' '--infodir=/usr/share/info' '--disable-dependency-tracking' '--with-gnu-ld' '--without-included-ltdl' '--without-sidplay2' '--without-oss' '--without-sndio' '--without-aac' '--without-mp3' '--with-bdb-dir=/usr' '--with-alsa' '--with-jack' '--with-magic' '--with-ncurses' '--with-ncursesw' '--with-samplerate' '--with-ffmpeg' '--with-flac' '--with-modplug' '--with-musepack' '--with-rcc' '--with-sndfile' '--with-speex' '--with-timidity' '--with-vorbis' '--with-wavpack' '--with-curl' '--disable-static' 'build_alias=x86_64-suse-linux-gnu' 'host_alias=x86_64-suse-linux-gnu' 'CFLAGS=-O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -Werror=return-type -flto=auto -g' 'LDFLAGS=-flto=auto' 'CXXFLAGS=-O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -Werror=return-type -flto=auto -g' 'PKG_CONFIG_PATH=:/usr/lib64/pkgconfig:/usr/share/pkgconfig' Mar 28 18:55:17.560868: main.c:1196 main(): Running on: Linux 5.16.15-1-default x86_64 mar 28 18:55:17.561416: main.c:1148 log_command_line(): mocp -D mar 28 18:55:17.561483: main.c:1162 log_popt_command_line(): mocp --debug mar 28 18:55:17.591749: decoder.c:700 load_plugins(): Loaded 9 decoders: ffmpeg flac modplug musepack sndfile speex timidity vorbis wavpack mar 28 18:55:17.591947: interface.c:3496 init_interface(): Starting MOC Interface mar 28 18:55:17.592047: log.c:233 log_init_stream(): Writing log to: mocp_client_log mar 28 18:55:17.592207: utf8.c:328 utf8_init(): Using UTF8 output -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1197614 http://bugzilla.opensuse.org/show_bug.cgi?id=1197614#c1 --- Comment #1 from Victor hck <victorhck@opensuse.org> --- Added the patch in build.opensuse.org and submitted a request: https://build.opensuse.org/request/show/965747 -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1197614 http://bugzilla.opensuse.org/show_bug.cgi?id=1197614#c2 Stanislav Brabec <sbrabec@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |IN_PROGRESS --- Comment #2 from Stanislav Brabec <sbrabec@suse.com> --- As far as I understand, Factory is already fixed. And this bug does not affect systems with older glibc. So we don't need to backport for Leap 15.4 and older. We should just keep it in track for Leap 15.5 (if it will happen and will have a newer glibc). Or upgrade/fix in advance. -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1197614 http://bugzilla.opensuse.org/show_bug.cgi?id=1197614#c4 --- Comment #4 from Victor hck <victorhck@opensuse.org> --- (In reply to Petr Gajdos from comment #3)
Hi Victor and Bj�rn:
I see you were contributing to multimedia:apps/moc recently. Stanislav is on long leave, so he will not be able to maintain it. Could you please take over this bug and eventually over this package?
Alternatively, I can fill the drop request as it seems the upstream is not truly active: ------------------------------------------------------------------------ r3005 | jcf | 2019-09-14 05:06:11 +0200 (Sat, 14 Sep 2019) | 6 lines
What do you think?
Hello! I'm just a simple user who enjoys mocp player! Don't know if I could maintain properly that package since I'm not a developer or such... -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1197614 http://bugzilla.opensuse.org/show_bug.cgi?id=1197614#c6 --- Comment #6 from Victor hck <victorhck@opensuse.org> --- (In reply to Petr Gajdos from comment #5)
The crucial thing is your motivation, not the actual knowledge, believe me.
do you think so?? It's really hard trying to fix .spec files or such...
I didn't see this particular piece of software, but anytime you can try ask me directly for help, or I think anytime you can involve opensuse-factory@ or other lists.
Well, I've using cmus for a while... but I still prefer mocp... so would be sad left this software dropped from openSUSE repositories... so maybe I can take over this package. Greetings! PS: I reply your comments since bugzilla.o.o I can't login in bugzilla.suse.o -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@suse.com