Two memory handling issues were found in gst-plugins-good0.10, a collection of GStreamer plugins from the "good" set: . Package : gst-plugins-good0.10 Version : 0.10.31-3+nmu4+deb8u3 CVE ID : CVE-2016-10198 CVE-2017-5840 Two memory handling issues were found in gst-plugins-good0.10, a collection of GStreamer plugins from the "good" set: CVE-2016-10198 An invalid read can be triggered in the aacparse element via a maliciously crafted file. CVE-2017-5840 An out of bounds heap read can be triggered in the qtdemux element via a maliciously crafted file. For Debian 8 "Jessie", these problems have been fixed in version 0.10.31-3+nmu4+deb8u3. We recommend that you upgrade your gst-plugins-good0.10 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Security vulnerabilities addressed in libgtk2.0-0 package through Ubuntu LTS system update. Installation advised for safety measures.. gst-plugins-good0.10,Debian security update,memory handling issues,GStreamer plugins,system upgrade. . LinuxSecurity.com Team
New GStreamer release. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-a7373b6432 2017-05-14 20:16:27.405820 --------------------------------------------------------------------------------Name : gstreamer1-plugin-mpg123 Product : Fedora 26 Version : 1.12.0 Release : 1.fc26 URL : https://gstreamer.freedesktop.org/ Summary : GStreamer plug-in for mp3 support through mpg123 Description : GStreamer plug-in for mp3 support through mpeg123. --------------------------------------------------------------------------------Update Information: New GStreamer release --------------------------------------------------------------------------------References: [ 1 ] Bug #1353377 - python-gstreamer1-1.12.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=1353377 [ 2 ] Bug #1419616 - CVE-2017-5843 CVE-2017-5848 gstreamer1-plugins-bad-free: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1419616 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade gstreamer1-plugin-mpg123' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.