Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

openSUSE Leap 15.2: openSUSE-SU-2021:0822-1 Critical: Gstreamer Threat

opensuse
Calendar Grey June 1, 2021
Dist Opensuse Esm H88
A significant security patch for VLC and its add-ons in openSUSE tackles a serious risk and multiple weaknesses.
An update that fixes one vulnerability, contains one feature is now available

Description

This update for gstreamer, gstreamer-plugins-bad, gstreamer-plugins-base,

gstreamer-plugins-good, gstreamer-plugins-ugly fixes the following issues:

gstreamer was updated to version 1.16.3 (bsc#1181255):

- delay creation of threadpools

- bin: Fix `deep-element-removed` log message

- buffer: fix meta sequence number fallback on rpi

- bufferlist: foreach: always remove as parent if buffer is changed

- bus: Make setting/replacing/clearing the sync handler thread-safe

- elementfactory: Fix missing features in case a feature moves to another

filename

- element: When removing a ghost pad also unset its target

- meta: intern registered impl string

- registry: Use a toolchain-specific registry file on Windows

- systemclock: Invalid internal time calculation causes non-increasing

clock time on Windows

- value: don't write to `const char *`

- value: Fix segfault comparing empty GValueArrays

- Revert floating enforcing

- aggregator:...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.2:

zypper in -t patch openSUSE-2021-822=1

Package List

- openSUSE Leap 15.2 (i586 x86_64):

gstreamer-1.16.3-lp152.2.3.1

gstreamer-debuginfo-1.16.3-lp152.2.3.1

gstreamer-debugsource-1.16.3-lp152.2.3.1

gstreamer-devel-1.16.3-lp152.2.3.1

gstreamer-doc-1.16.3-lp152.2.3.1

gstreamer-plugins-bad-1.16.3-lp152.3.3.1

gstreamer-plugins-bad-chromaprint-1.16.3-lp152.3.3.1

gstreamer-plugins-bad-chromaprint-debuginfo-1.16.3-lp152.3.3.1

gstreamer-plugins-bad-debuginfo-1.16.3-lp152.3.3.1

gstreamer-plugins-bad-debugsource-1.16.3-lp152.3.3.1

gstreamer-plugins-bad-devel-1.16.3-lp152.3.3.1

gstreamer-plugins-bad-doc-1.16.3-lp152.3.3.1

gstreamer-plugins-bad-fluidsynth-1.16.3-lp152.3.3.1

gstreamer-plugins-bad-fluidsynth-debuginfo-1.16.3-lp152.3.3.1

gstreamer-plugins-base-1.16.3-lp152.3.3.1

gstreamer-plugins-base-debuginfo-1.16.3-lp152.3.3.1

gstreamer-plugins-base-debugsource-1.16.3-lp152.3.3.1

gstreamer-plugins-base-devel-1.16.3-lp152.3.3.1

gstreamer-plugins-base-doc-1.16.3-lp152.3.3.1

gstreamer-plugins-good-1.16.3-lp152.2.3.1

gstreamer-plugins-good-debuginfo-1.16.3-lp152.2.3.1

gstrea...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2021-3185.html

https://bugzilla.suse.com/1181255

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2021:0822-1
Rating: important
Affected Products: openSUSE Leap 15.2 ble.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here