This update for gstreamer-plugins-bad fixes the following issues:
- CVE-2023-37329: Fixed GStreamer SRT File Parsing Heap-based Buffer
Overflow (bsc#1213126).
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.5:
zypper in -t patch openSUSE-2023-379=1
- openSUSE Leap 15.4:
zypper in -t patch openSUSE-2023-379=1
- openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64):
gstreamer-plugins-bad-1.22.0-lp155.3.4.1
gstreamer-plugins-bad-chromaprint-1.22.0-lp155.3.4.1
gstreamer-plugins-bad-chromaprint-debuginfo-1.22.0-lp155.3.4.1
gstreamer-plugins-bad-debuginfo-1.22.0-lp155.3.4.1
gstreamer-plugins-bad-debugsource-1.22.0-lp155.3.4.1
gstreamer-plugins-bad-devel-1.22.0-lp155.3.4.1
gstreamer-plugins-bad-fluidsynth-1.22.0-lp155.3.4.1
gstreamer-plugins-bad-fluidsynth-debuginfo-1.22.0-lp155.3.4.1
gstreamer-transcoder-1.22.0-lp155.3.4.1
gstreamer-transcoder-debuginfo-1.22.0-lp155.3.4.1
gstreamer-transcoder-devel-1.22.0-lp155.3.4.1
libgstadaptivedemux-1_0-0-1.22.0-lp155.3.4.1
libgstadaptivedemux-1_0-0-debuginfo-1.22.0-lp155.3.4.1
libgstbadaudio-1_0-0-1.22.0-lp155.3.4.1
libgstbadaudio-1_0-0-debuginfo-1.22.0-lp155.3.4.1
libgstbasecamerabinsrc-1_0-0-1.22.0-lp155.3.4.1
libgstbasecamerabinsrc-1_0-0-debuginfo-1.22.0-lp155.3.4.1
libgstcodecparsers-1_0-0-1.22.0-lp155.3.4.1
libgstcodecparsers-1_0-0-debuginfo-1.22.0-lp155.3.4.1
libgstcode...
Read the Full Advisoryhttps://www.suse.com/security/cve/CVE-2023-37329.html
https://bugzilla.suse.com/1213126
Get the latest Linux and open source security news straight to your inbox.