Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Fedora 25 High Severity: GStreamer Security Update for Critical Issues

fedora
Calendar Grey February 20, 2017
Scroller Fedora
Important patch for mingw-gstreamer1-plugins-base resolves significant vulnerabilities in Fedora 25, enhancing overall protection.
Security fix for CVE-2017-5837, CVE-2017-5839, CVE-2017-5842, CVE-2017-5844 - Downgrade to 1.10.3 as it is the latest stable release

Summary

GStreamer is a streaming media framework, based on graphs of filters which

operate on media data. Applications using this library can do anything

from real-time sound processing to playing videos, and just about anything

else media-related. Its plugin-based architecture means that new data

types or processing capabilities can be added simply by installing new

plug-ins.

This package contains a set of well-maintained base plug-ins.

Update Information:

Security fix for CVE-2017-5837, CVE-2017-5839, CVE-2017-5842, CVE-2017-5844 - Downgrade to 1.10.3 as it is the latest stable release

Change Log

References


[ 1 ] Bug #1419584 - CVE-2017-5837 gstreamer-plugins-base: Floating point exception in gst_riff_create_audio_caps https://bugzilla.redhat.com/show_bug.cgi?id=1419584 [ 2 ] Bug #1419586 - CVE-2017-5839 gstreamer-plugins-base: Stack overflow in gst_riff_create_audio_caps https://bugzilla.redhat.com/show_bug.cgi?id=1419586 [ 3 ] Bug #1419591 - CVE-2017-5842 gstreamer-plugins-base: Out-of-bounds heap read in html_context_handle_element https://bugzilla.redhat.com/show_bug.cgi?id=1419591 [ 4 ] Bug #1419600 - CVE-2017-5844 gstreamer-plugins-base: Floating point exception in gst_riff_create_audio_caps https://bugzilla.redhat.com/show_bug.cgi?id=1419600

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade mingw-gstreamer1-plugins-base' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
important
Lowest
Low
Medium
High
Critical

Name: mingw-gstreamer1-plugins-base
Product: Fedora 25
Version: 1.10.3
Release: 1.fc25
Summary: Cross compiled GStreamer1 media framework base plug-ins

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.