Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

SUSE 12-SP2: SUSE-SU-2016:3303-1 Important: GStreamer Plugins Good

suse
Calendar Grey December 30, 2016
Dist Suse Esm H88
Ubuntu Security Patch for libgstreamer fixes various vulnerabilities. Make sure your device is current to maintain security.
An update that fixes 6 vulnerabilities is now available

Summary

This update for gstreamer-plugins-good fixes the following security issues: - CVE-2016-9807: Flic decoder invalid read could lead to crash. (bsc#1013655) - CVE-2016-9634: Flic out-of-bounds write could lead to code execution. (bsc#1012102) - CVE-2016-9635: Flic out-of-bounds write could lead to code execution. (bsc#1012103) - CVE-2016-9635: Flic out-of-bounds write could lead to code execution. (bsc#1012104) - CVE-2016-9808: A maliciously crafted flic file can still cause invalid memory accesses. (bsc#1013653) - CVE-2016-9810: A maliciously crafted flic file can still cause invalid memory accesses. (bsc#1013663) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product:

References

#1012102 #1012103 #1012104 #1013653 #1013655

#1013663

Cross- CVE-2016-9634 CVE-2016-9635 CVE-2016-9636

CVE-2016-9807 CVE-2016-9808 CVE-2016-9810

Affected Products:

SUSE Linux Enterprise Server for Raspberry Pi 12-SP2

SUSE Linux Enterprise Server 12-SP2

SUSE Linux Enterprise Desktop 12-SP2

https://www.suse.com/security/cve/CVE-2016-9634.html

https://www.suse.com/security/cve/CVE-2016-9635.html

https://www.suse.com/security/cve/CVE-2016-9636.html

https://www.suse.com/security/cve/CVE-2016-9807.html

https://www.suse.com/security/cve/CVE-2016-9808.html

https://www.suse.com/security/cve/CVE-2016-9810.html

https://bugzilla.suse.com/1012102

https://bugzilla.suse.com/1012103

https://bugzilla.suse.com/1012104

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:3303-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here