This update for gstreamer-plugins-bad fixes the following issues:
Adding references for already fixed vulnerability:
- CVE-2023-50186: Fixed heap-based buffer overflow in the AV1 codec parser
(ZDI-CAN-22300, bsc#1218534, bsc#1223263)
- CVE-2023-40475: Fixed GStreamer MXF File Parsing Integer Overflow
(bsc#1215792).
- CVE-2023-44446: Fixed GStreamer MXF File Parsing Use-After-Free
(bsc#1217213).
- CVE-2023-44429: Fixed GStreamer AV1 Codec Parsing Heap-based Buffer
Overflow (bsc#1217211).
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.5:
zypper in -t patch openSUSE-2024-305=1
- openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64):
gstreamer-plugins-bad-1.22.0-lp155.3.10.1
gstreamer-plugins-bad-chromaprint-1.22.0-lp155.3.10.1
gstreamer-plugins-bad-chromaprint-debuginfo-1.22.0-lp155.3.10.1
gstreamer-plugins-bad-debuginfo-1.22.0-lp155.3.10.1
gstreamer-plugins-bad-debugsource-1.22.0-lp155.3.10.1
gstreamer-plugins-bad-devel-1.22.0-lp155.3.10.1
gstreamer-plugins-bad-fluidsynth-1.22.0-lp155.3.10.1
gstreamer-plugins-bad-fluidsynth-debuginfo-1.22.0-lp155.3.10.1
gstreamer-transcoder-1.22.0-lp155.3.10.1
gstreamer-transcoder-debuginfo-1.22.0-lp155.3.10.1
gstreamer-transcoder-devel-1.22.0-lp155.3.10.1
libgstadaptivedemux-1_0-0-1.22.0-lp155.3.10.1
libgstadaptivedemux-1_0-0-debuginfo-1.22.0-lp155.3.10.1
libgstbadaudio-1_0-0-1.22.0-lp155.3.10.1
libgstbadaudio-1_0-0-debuginfo-1.22.0-lp155.3.10.1
libgstbasecamerabinsrc-1_0-0-1.22.0-lp155.3.10.1
libgstbasecamerabinsrc-1_0-0-debuginfo-1.22.0-lp155.3.10.1
libgstcodecparsers-1_0-0-1.22.0-lp155.3.10.1
libgstcodecparsers-1_0-0-debuginfo-1.22.0-lp1...
Read the Full Advisoryhttps://www.suse.com/security/cve/CVE-2023-40475.html
https://www.suse.com/security/cve/CVE-2023-44429.html
https://www.suse.com/security/cve/CVE-2023-44446.html
https://www.suse.com/security/cve/CVE-2023-50186.html
https://bugzilla.suse.com/1215792
https://bugzilla.suse.com/1217211
https://bugzilla.suse.com/1217213
https://bugzilla.suse.com/1218534
https://bugzilla.suse.com/1223263
Get the latest Linux and open source security news straight to your inbox.