An issue in MPV v.0.29.1 fixed in v0.30 allows attackers to execute arbitrary code and crash program via the ao_c parameter.
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
Link | Tags |
---|---|
https://github.com/mpv-player/mpv/issues/6808 | issue tracking exploit |
https://lists.debian.org/debian-lts-announce/2023/03/msg00009.html | mailing list |