-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Moderate: gstreamer1-plugins-good security update
Advisory ID:       RHSA-2023:2260-01
Product:           Red Hat Enterprise Linux
Advisory URL:      https://access.redhat.com/errata/RHSA-2023:2260
Issue date:        2023-05-09
CVE Names:         CVE-2022-1920 CVE-2022-1921 CVE-2022-1922 
                   CVE-2022-1923 CVE-2022-1924 CVE-2022-1925 
                   CVE-2022-2122 
====================================================================
1. Summary:

An update for gstreamer1-plugins-good is now available for Red Hat
Enterprise Linux 9.

Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AppStream (v. 9) - aarch64, ppc64le, s390x, x86_64

3. Description:

GStreamer is a streaming media framework based on graphs of filters which
operate on media data. The gstreamer1-plugins-good packages contain a
collection of well-supported plug-ins of good quality and under the LGPL
license.

Security Fix(es):

* gstreamer-plugins-good: Potential heap overwrite in
gst_matroska_demux_add_wvpk_header() (CVE-2022-1920)

* gstreamer-plugins-good: Heap-based buffer overflow in the avi demuxer
when handling certain AVI files (CVE-2022-1921)

* gstreamer-plugins-good: Potential heap overwrite in mkv demuxing using
zlib decompression (CVE-2022-1922)

* gstreamer-plugins-good: Potential heap overwrite in mkv demuxing using
bz2 decompression (CVE-2022-1923)

* gstreamer-plugins-good: Potential heap overwrite in mkv demuxing using
lzo decompression (CVE-2022-1924)

* gstreamer-plugins-good: Potential heap overwrite in mkv demuxing using
HEADERSTRIP decompression (CVE-2022-1925)

* gstreamer-plugins-good: Potential heap overwrite in mp4 demuxing using
zlib decompression (CVE-2022-2122)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Red Hat
Enterprise Linux 9.2 Release Notes linked from the References section.

4. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258

5. Bugs fixed (https://bugzilla.redhat.com/):

2130935 - CVE-2022-1920 gstreamer-plugins-good: Potential heap overwrite in gst_matroska_demux_add_wvpk_header()
2130949 - CVE-2022-1921 gstreamer-plugins-good: Heap-based buffer overflow in the avi demuxer when handling certain AVI files
2130955 - CVE-2022-1922 gstreamer-plugins-good: Potential heap overwrite in mkv demuxing using zlib decompression
2130959 - CVE-2022-1923 gstreamer-plugins-good: Potential heap overwrite in mkv demuxing using bz2 decompression
2131003 - CVE-2022-1924 gstreamer-plugins-good: Potential heap overwrite in mkv demuxing using lzo decompression
2131007 - CVE-2022-1925 gstreamer-plugins-good: Potential heap overwrite in mkv demuxing using HEADERSTRIP decompression
2131018 - CVE-2022-2122 gstreamer-plugins-good: Potential heap overwrite in mp4 demuxing using zlib decompression

6. Package List:

Red Hat Enterprise Linux AppStream (v. 9):

Source:
gstreamer1-plugins-good-1.18.4-6.el9.src.rpm

aarch64:
gstreamer1-plugins-good-1.18.4-6.el9.aarch64.rpm
gstreamer1-plugins-good-debuginfo-1.18.4-6.el9.aarch64.rpm
gstreamer1-plugins-good-debugsource-1.18.4-6.el9.aarch64.rpm
gstreamer1-plugins-good-gtk-1.18.4-6.el9.aarch64.rpm
gstreamer1-plugins-good-gtk-debuginfo-1.18.4-6.el9.aarch64.rpm
gstreamer1-plugins-good-qt-debuginfo-1.18.4-6.el9.aarch64.rpm

ppc64le:
gstreamer1-plugins-good-1.18.4-6.el9.ppc64le.rpm
gstreamer1-plugins-good-debuginfo-1.18.4-6.el9.ppc64le.rpm
gstreamer1-plugins-good-debugsource-1.18.4-6.el9.ppc64le.rpm
gstreamer1-plugins-good-gtk-1.18.4-6.el9.ppc64le.rpm
gstreamer1-plugins-good-gtk-debuginfo-1.18.4-6.el9.ppc64le.rpm
gstreamer1-plugins-good-qt-debuginfo-1.18.4-6.el9.ppc64le.rpm

s390x:
gstreamer1-plugins-good-1.18.4-6.el9.s390x.rpm
gstreamer1-plugins-good-debuginfo-1.18.4-6.el9.s390x.rpm
gstreamer1-plugins-good-debugsource-1.18.4-6.el9.s390x.rpm
gstreamer1-plugins-good-gtk-1.18.4-6.el9.s390x.rpm
gstreamer1-plugins-good-gtk-debuginfo-1.18.4-6.el9.s390x.rpm
gstreamer1-plugins-good-qt-debuginfo-1.18.4-6.el9.s390x.rpm

x86_64:
gstreamer1-plugins-good-1.18.4-6.el9.i686.rpm
gstreamer1-plugins-good-1.18.4-6.el9.x86_64.rpm
gstreamer1-plugins-good-debuginfo-1.18.4-6.el9.i686.rpm
gstreamer1-plugins-good-debuginfo-1.18.4-6.el9.x86_64.rpm
gstreamer1-plugins-good-debugsource-1.18.4-6.el9.i686.rpm
gstreamer1-plugins-good-debugsource-1.18.4-6.el9.x86_64.rpm
gstreamer1-plugins-good-gtk-1.18.4-6.el9.i686.rpm
gstreamer1-plugins-good-gtk-1.18.4-6.el9.x86_64.rpm
gstreamer1-plugins-good-gtk-debuginfo-1.18.4-6.el9.i686.rpm
gstreamer1-plugins-good-gtk-debuginfo-1.18.4-6.el9.x86_64.rpm
gstreamer1-plugins-good-qt-debuginfo-1.18.4-6.el9.i686.rpm
gstreamer1-plugins-good-qt-debuginfo-1.18.4-6.el9.x86_64.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

7. References:

https://access.redhat.com/security/cve/CVE-2022-1920
https://access.redhat.com/security/cve/CVE-2022-1921
https://access.redhat.com/security/cve/CVE-2022-1922
https://access.redhat.com/security/cve/CVE-2022-1923
https://access.redhat.com/security/cve/CVE-2022-1924
https://access.redhat.com/security/cve/CVE-2022-1925
https://access.redhat.com/security/cve/CVE-2022-2122
https://access.redhat.com/security/updates/classification/#moderate
https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/9.2_release_notes/index

8. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2023 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBZFo06dzjgjWX9erEAQhrwQ//Ux/jfIsdlOlcSYh49YQrv5mmRH639gQE
TVDDFz5x/9zRwuos1650/zyEs5SF3F9pBFgc8FeU9V2styVUuIYTgKtI3vYexa48
LfoWcFZhVHNq60onLmoH/1TJsIdPA5Lvdmk2kqMn0+dA77CD9EAviilfWkTDp27F
I1fTX0L0S8d7JZAscwMsrCefItv/5LG+tH2bN6ZokA21aV1RkLqaKylJdZj5+m2y
dSyelBeEidfQTxaj9CNZftOrQjDziyW6JFVfQna2sOuz7ejOMUkfy25ZH145M9Y6
0P7S71w+8FVk76AlrKE3qGyh0V13dfHTQpZW6cca4yzrKmoH2G4EDFHo0g9PrSwD
eKFRmnJ6VNkyc4lgQT7G5ME1PsNYlRsX5WAUKWzT8RaIcxIWDr96UhoeKC2gYiaW
wr/aOcBij0NZkdWN+9NbnXZqrwIRPTe8dOJpQpO9Nojsev4o7LZhWdS1z5C0xwsu
wdPIlMofZ8/x01z39b/CVPsmESk0kefw7w5rwj+9XO2QcXwZkrshpZM8tMjhrMlF
WyEOPPli2WpQfjco/jiMhV8cjKHSCHQSYPt67QZXtUFqD68P8AI1RhX9K7VhPVRo
gOTkEsGxwqp2uLiTvYc7kElDjbKD/6nd52MANo4TR4aO2sZsTylCNeQ7I2bROhE4
krFzi7LnE2s=IWWY
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2023-2260:01 Moderate: gstreamer1-plugins-good security update

An update for gstreamer1-plugins-good is now available for Red Hat Enterprise Linux 9

Summary

GStreamer is a streaming media framework based on graphs of filters which operate on media data. The gstreamer1-plugins-good packages contain a collection of well-supported plug-ins of good quality and under the LGPL license.
Security Fix(es):
* gstreamer-plugins-good: Potential heap overwrite in gst_matroska_demux_add_wvpk_header() (CVE-2022-1920)
* gstreamer-plugins-good: Heap-based buffer overflow in the avi demuxer when handling certain AVI files (CVE-2022-1921)
* gstreamer-plugins-good: Potential heap overwrite in mkv demuxing using zlib decompression (CVE-2022-1922)
* gstreamer-plugins-good: Potential heap overwrite in mkv demuxing using bz2 decompression (CVE-2022-1923)
* gstreamer-plugins-good: Potential heap overwrite in mkv demuxing using lzo decompression (CVE-2022-1924)
* gstreamer-plugins-good: Potential heap overwrite in mkv demuxing using HEADERSTRIP decompression (CVE-2022-1925)
* gstreamer-plugins-good: Potential heap overwrite in mp4 demuxing using zlib decompression (CVE-2022-2122)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Red Hat Enterprise Linux 9.2 Release Notes linked from the References section.



Summary


Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258

References

https://access.redhat.com/security/cve/CVE-2022-1920 https://access.redhat.com/security/cve/CVE-2022-1921 https://access.redhat.com/security/cve/CVE-2022-1922 https://access.redhat.com/security/cve/CVE-2022-1923 https://access.redhat.com/security/cve/CVE-2022-1924 https://access.redhat.com/security/cve/CVE-2022-1925 https://access.redhat.com/security/cve/CVE-2022-2122 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/9.2_release_notes/index

Package List

Red Hat Enterprise Linux AppStream (v. 9):
Source: gstreamer1-plugins-good-1.18.4-6.el9.src.rpm
aarch64: gstreamer1-plugins-good-1.18.4-6.el9.aarch64.rpm gstreamer1-plugins-good-debuginfo-1.18.4-6.el9.aarch64.rpm gstreamer1-plugins-good-debugsource-1.18.4-6.el9.aarch64.rpm gstreamer1-plugins-good-gtk-1.18.4-6.el9.aarch64.rpm gstreamer1-plugins-good-gtk-debuginfo-1.18.4-6.el9.aarch64.rpm gstreamer1-plugins-good-qt-debuginfo-1.18.4-6.el9.aarch64.rpm
ppc64le: gstreamer1-plugins-good-1.18.4-6.el9.ppc64le.rpm gstreamer1-plugins-good-debuginfo-1.18.4-6.el9.ppc64le.rpm gstreamer1-plugins-good-debugsource-1.18.4-6.el9.ppc64le.rpm gstreamer1-plugins-good-gtk-1.18.4-6.el9.ppc64le.rpm gstreamer1-plugins-good-gtk-debuginfo-1.18.4-6.el9.ppc64le.rpm gstreamer1-plugins-good-qt-debuginfo-1.18.4-6.el9.ppc64le.rpm
s390x: gstreamer1-plugins-good-1.18.4-6.el9.s390x.rpm gstreamer1-plugins-good-debuginfo-1.18.4-6.el9.s390x.rpm gstreamer1-plugins-good-debugsource-1.18.4-6.el9.s390x.rpm gstreamer1-plugins-good-gtk-1.18.4-6.el9.s390x.rpm gstreamer1-plugins-good-gtk-debuginfo-1.18.4-6.el9.s390x.rpm gstreamer1-plugins-good-qt-debuginfo-1.18.4-6.el9.s390x.rpm
x86_64: gstreamer1-plugins-good-1.18.4-6.el9.i686.rpm gstreamer1-plugins-good-1.18.4-6.el9.x86_64.rpm gstreamer1-plugins-good-debuginfo-1.18.4-6.el9.i686.rpm gstreamer1-plugins-good-debuginfo-1.18.4-6.el9.x86_64.rpm gstreamer1-plugins-good-debugsource-1.18.4-6.el9.i686.rpm gstreamer1-plugins-good-debugsource-1.18.4-6.el9.x86_64.rpm gstreamer1-plugins-good-gtk-1.18.4-6.el9.i686.rpm gstreamer1-plugins-good-gtk-1.18.4-6.el9.x86_64.rpm gstreamer1-plugins-good-gtk-debuginfo-1.18.4-6.el9.i686.rpm gstreamer1-plugins-good-gtk-debuginfo-1.18.4-6.el9.x86_64.rpm gstreamer1-plugins-good-qt-debuginfo-1.18.4-6.el9.i686.rpm gstreamer1-plugins-good-qt-debuginfo-1.18.4-6.el9.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/


Severity
Advisory ID: RHSA-2023:2260-01
Product: Red Hat Enterprise Linux
Advisory URL: https://access.redhat.com/errata/RHSA-2023:2260
Issued Date: : 2023-05-09
CVE Names: CVE-2022-1920 CVE-2022-1921 CVE-2022-1922 CVE-2022-1923 CVE-2022-1924 CVE-2022-1925 CVE-2022-2122

Topic

An update for gstreamer1-plugins-good is now available for Red HatEnterprise Linux 9.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures

Red Hat Enterprise Linux AppStream (v. 9) - aarch64, ppc64le, s390x, x86_64


Bugs Fixed

2130935 - CVE-2022-1920 gstreamer-plugins-good: Potential heap overwrite in gst_matroska_demux_add_wvpk_header()

2130949 - CVE-2022-1921 gstreamer-plugins-good: Heap-based buffer overflow in the avi demuxer when handling certain AVI files

2130955 - CVE-2022-1922 gstreamer-plugins-good: Potential heap overwrite in mkv demuxing using zlib decompression

2130959 - CVE-2022-1923 gstreamer-plugins-good: Potential heap overwrite in mkv demuxing using bz2 decompression

2131003 - CVE-2022-1924 gstreamer-plugins-good: Potential heap overwrite in mkv demuxing using lzo decompression

2131007 - CVE-2022-1925 gstreamer-plugins-good: Potential heap overwrite in mkv demuxing using HEADERSTRIP decompression

2131018 - CVE-2022-2122 gstreamer-plugins-good: Potential heap overwrite in mp4 demuxing using zlib decompression


Related News