Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Fedora 39: FEDORA-2024-919bc7e512 Critical: GStreamer Buffer Overflow

fedora
Calendar Grey July 1, 2024
Dist Fedora Esm H88
The latest mingw-gstreamer1-plugins-base update in Fedora 39 features an essential backport remedy addressing buffer overflow vulnerabilities.
Update to gstreamer-1.22.9

Summary

GStreamer is a streaming media framework, based on graphs of filters which

operate on media data. Applications using this library can do anything

from real-time sound processing to playing videos, and just about anything

else media-related. Its plugin-based architecture means that new data

types or processing capabilities can be added simply by installing new

plug-ins.

This package contains a set of well-maintained base plug-ins.

Update Information:

Update to gstreamer-1.22.9. Backport fix for CVE-2024-0444.

Change Log

* Sat Jun 22 2024 Sandro Mani - 1.22.9-2 - Backport fix for CVE-2024-4453 * Sat Jan 27 2024 Sandro Mani - 1.22.9-1 - Update to 1.22.9 * Thu Jan 25 2024 Fedora Release Engineering - 1.22.8-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Sun Jan 21 2024 Fedora Release Engineering - 1.22.8-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Wed Dec 20 2023 Sandro Mani - 1.22.8-1 - Update to 1.22.8

References


[ 1 ] Bug #2283001 - CVE-2024-4453 mingw-gstreamer1: gstreamer: EXIF Metadata Parsing Integer Overflow [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2283001 [ 2 ] Bug #2292337 - CVE-2024-0444 mingw-gstreamer1: gstreamer: AV1 Video Parsing Stack-based Buffer Overflow [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2292337

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-919bc7e512' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: mingw-gstreamer1-plugins-base
Product: Fedora 39
Version: 1.22.9
Release: 2.fc39
Summary: Cross compiled GStreamer1 media framework base plug-ins

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here