GStreamer has an OOB-write in isomp4/qtdemux.c. (CVE-2024-47537) GStreamer has a stack-buffer overflow in vorbis_handle_identification_packet. (CVE-2024-47538) GStreamer has an OOB-write in convert_to_s334_1a. (CVE-2024-47539) GStreamer uses uninitialized stack memory in Matroska/WebM demuxer. . MGASA-2025-0040 - Updated gstreamer1.0, gstreamer1.0-plugins-base & gstreamer1.0-plugins-good packages fix security vulnerabilities Publication date: 06 Feb 2025 URL: https://advisories.mageia.org/MGASA-2025-0040.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-47537, CVE-2024-47538, CVE-2024-47539, CVE-2024-47540, CVE-2024-47541, CVE-2024-47542, CVE-2024-47543, CVE-2024-47544, CVE-2024-47545, CVE-2024-47546, CVE-2024-47596, CVE-2024-47597, CVE-2024-47598, CVE-2024-47599, CVE-2024-47600, CVE-2024-47601, CVE-2024-47602 GStreamer has an OOB-write in isomp4/qtdemux.c. (CVE-2024-47537) GStreamer has a stack-buffer overflow in vorbis_handle_identification_packet. (CVE-2024-47538) GStreamer has an OOB-write in convert_to_s334_1a. (CVE-2024-47539) GStreamer uses uninitialized stack memory in Matroska/WebM demuxer. (CVE-2024-47540) GStreamer has an out-of-bounds write in SSA subtitle parser. (CVE-2024-47541) GStreamer ID3v2 parser out-of-bounds read and NULL-pointer dereference. (CVE-2024-47542) GStreamer has an OOB-read in qtdemux_parse_container. (CVE-2024-47543) GStreamer has NULL-pointer dereferences in MP4/MOV demuxer CENC handling. (CVE-2024-47544) GStreamer has an integer underflow in FOURCC_strf parsing leading to OOB-read. (CVE-2024-47545) GStreamer has an integer underflow in extract_cc_from_data leading to OOB-read. (CVE-2024-47546) GStreamer has an OOB-read in FOURCC_SMI_ parsing. (CVE-2024-47596) GStreamer has an OOB-read in qtdemux_parse_samples. (CVE-2024-47597) GStreamer has an OOB-read in qtdemux_merge_sample_table. (CVE-2024-47598) GStreamer Insufficient error handling in JPEG decoder that can lead to NULL-pointerdereferences. (CVE-2024-47599) GStreamer has an OOB-read in format_channel_mask. (CVE-2024-47600) GStreamer has a NULL-pointer dereference in Matroska/WebM demuxer. (CVE-2024-47601) GStreamer NULL-pointer dereferences and out-of-bounds reads in Matroska/WebM demuxer. (CVE-2024-47602) GStreamer NULL-pointer dereference in Matroska/WebM demuxer. (CVE-2024-47603) GStreamer Integer overflows in MP4/MOV demuxer and memory allocator that can lead to out-of-bounds writes. (CVE-2024-47606) Stack-buffer overflow in gst_opus_dec_parse_header. (CVE-2024-47607) GStreamer has a null pointer dereference in gst_gdk_pixbuf_dec_flush. (CVE-2024-47613) GStreamer has an out-of-bounds write in Ogg demuxer. (CVE-2024-47615) GStreamer has an OOB-read in gst_avi_subtitle_parse_gab2_chunk. (CVE-2024-47774) GStreamer has an OOB-read in parse_ds64. (CVE-2024-47775) GStreamer has a OOB-read in gst_wavparse_cue_chunk. (CVE-2024-47776) GStreamer has an OOB-read in gst_wavparse_smpl_chunk. (CVE-2024-47777) GStreamer has an OOB-read in gst_wavparse_adtl_chunk. (CVE-2024-47778) Gstreamer Use-After-Free read in Matroska CodecPrivate. (CVE-2024-47834) Gstreamer NULL-pointer dereference in LRC subtitle parser. (CVE-2024-47835) References: - https://bugs.mageia.org/show_bug.cgi?id=33856 - https://www.openwall.com/lists/oss-security/2024/12/13/1 - https://lists.debian.org/debian-security-announce/2024/msg00247.html - https://lists.debian.org/debian-security-announce/2024/msg00248.html - https://lists.debian.org/debian-security-announce/2024/msg00254.html - https://ubuntu.com/security/notices/USN-7174-1 - https://ubuntu.com/security/notices/USN-7174-1 - https://ubuntu.com/security/notices/USN-7176-1 - https://www.cve.org/CVERecord?id=CVE-2024-47537 - https://www.cve.org/CVERecord?id=CVE-2024-47538 - https://www.cve.org/CVERecord?id=CVE-2024-47539 - https://www.cve.org/CVERecord?id=CVE-2024-47540 - https://www.cve.org/CVERecord?id=CVE-2024-47541 - https://www.cve.org/CVERecord?id=CVE-2024-47542 - https://www.cve.org/CVERecord?id=CVE-2024-47543 -https://www.cve.org/CVERecord?id=CVE-2024-47544 - https://www.cve.org/CVERecord?id=CVE-2024-47545 - https://www.cve.org/CVERecord?id=CVE-2024-47546 - https://www.cve.org/CVERecord?id=CVE-2024-47596 - https://www.cve.org/CVERecord?id=CVE-2024-47597 - https://www.cve.org/CVERecord?id=CVE-2024-47598 - https://www.cve.org/CVERecord?id=CVE-2024-47599 - https://www.cve.org/CVERecord?id=CVE-2024-47600 - https://www.cve.org/CVERecord?id=CVE-2024-47601 - https://www.cve.org/CVERecord?id=CVE-2024-47602 SRPMS: - 9/core/gstreamer1.0-1.22.11-1.1.mga9 - 9/core/gstreamer1.0-plugins-base-1.22.11-1.2.mga9 - 9/core/gstreamer1.0-plugins-good-1.22.11-1.1.mga9 . New versions of gstreamer1.0 along with its plugins have been released to address severe security vulnerabilities, specifically concerning out-of-bounds writes and memory management issues.. GStreamer Updates, Mageia Security, OOB Write Issues, Stack Buffer Overflow, Media Player Security. . Severity: Critical. LinuxSecurity.com Team
Multiple vulnerabilities have been discovered in VLC, the worst of which could result in arbitrary code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202409-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: VLC: Multiple Vulnerabilities Date: September 22, 2024 Bugs: #788226, #883943, #917274 ID: 202409-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in VLC, the worst of which could result in arbitrary code execution. Background ========== VLC is a cross-platform media player and streaming server. Affected packages ================= Package Vulnerable Unaffected --------------- ------------ ------------ media-video/vlc < 3.0.20 > = 3.0.20 Description =========== Multiple vulnerabilities have been discovered in VLC. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All VLC users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-video/vlc-3.0.20" References ========== [ 1 ] CVE-2022-41325 https://nvd.nist.gov/vuln/detail/CVE-2022-41325 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202409-17 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
A buffer overflow was discovered in the MMS module of the VLC media player. For the oldstable distribution (bullseye), this problem has been fixed . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5707-1
Multiple vulnerabilities have been discovered in Kodi, a media-player and entertainment hub. CVE-2017-5982 . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3712-1
- digiKam-8.0.0 - enabled MediaPlayer - Security fix for CVE-2023-1729 https://www.digikam.org/news/2023-04-16-8.0.0_release_announcement/. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-573f6adf01 2023-05-08 00:52:45.201089 --------------------------------------------------------------------------------Name : digikam Product : Fedora 36 Version : 8.0.0 Release : 2.fc36 URL : https://www.digikam.org/ Summary : A digital camera accessing & photo management application Description : digiKam is an easy to use and powerful digital photo management application, which makes importing, organizing and manipulating digital photos a "snap". An easy to use interface is provided to connect to your digital camera, preview the images and download and/or delete them. digiKam built-in image editor makes the common photo correction a simple task. --------------------------------------------------------------------------------Update Information: - digiKam-8.0.0 - enabled MediaPlayer - Security fix for CVE-2023-1729 https://www.digikam.org/news/2023-04-16-8.0.0_release_announcement/ --------------------------------------------------------------------------------ChangeLog: * Sat Apr 15 2023 Alexey Kurov - 8.0.0-2 - fixed crash in MediaPlayer * Thu Apr 13 2023 Alexey Kurov - 8.0.0-1 - digiKam-8.0.0 - enabled MediaPlayer - BR: kf5-sonnet-devel --------------------------------------------------------------------------------References: [ 1 ] Bug #2188275 - CVE-2023-1729 digikam: LibRaw: a heap-buffer-overflow in raw2image_ex() [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2188275 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-573f6adf01' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
- digiKam-8.0.0 - enabled MediaPlayer - Security fix for CVE-2023-1729 https://www.digikam.org/news/2023-04-16-8.0.0_release_announcement/. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-2c75a3bd51 2023-05-08 00:41:27.908335 --------------------------------------------------------------------------------Name : digikam Product : Fedora 37 Version : 8.0.0 Release : 2.fc37 URL : https://www.digikam.org/ Summary : A digital camera accessing & photo management application Description : digiKam is an easy to use and powerful digital photo management application, which makes importing, organizing and manipulating digital photos a "snap". An easy to use interface is provided to connect to your digital camera, preview the images and download and/or delete them. digiKam built-in image editor makes the common photo correction a simple task. --------------------------------------------------------------------------------Update Information: - digiKam-8.0.0 - enabled MediaPlayer - Security fix for CVE-2023-1729 https://www.digikam.org/news/2023-04-16-8.0.0_release_announcement/ --------------------------------------------------------------------------------ChangeLog: * Sat Apr 15 2023 Alexey Kurov - 8.0.0-2 - fixed crash in MediaPlayer * Thu Apr 13 2023 Alexey Kurov - 8.0.0-1 - digiKam-8.0.0 - enabled MediaPlayer - BR: kf5-sonnet-devel --------------------------------------------------------------------------------References: [ 1 ] Bug #2188275 - CVE-2023-1729 digikam: LibRaw: a heap-buffer-overflow in raw2image_ex() [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2188275 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-2c75a3bd51' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
FFmpeg 6.0 upgrade. ---- update to 111.0.5563.64. Fixes the following security issues: CVE-2023-0927 CVE-2023-0928 CVE-2023-0929 CVE-2023-0930 CVE-2023-0931 CVE-2023-0932 CVE-2023-0933 CVE-2023-0941 CVE-2023-1213 CVE-2023-1214 CVE-2023-1215 CVE-2023-1216 CVE-2023-1217 CVE-2023-1218 CVE-2023-1219 CVE-2023-1220 CVE-2023-1221 CVE-2023-1222 CVE-2023-1223. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-a5e10b188a 2023-03-14 00:16:44.047436 --------------------------------------------------------------------------------Name : mpv Product : Fedora 38 Version : 0.35.1 Release : 3.fc38 URL : https://mpv.io/ Summary : Movie player playing most video formats and DVDs Description : Mpv is a movie player based on MPlayer and mplayer2. It supports a wide variety of video file formats, audio and video codecs, and subtitle types. Special input URL types are available to read input from a variety of sources other than disk files. Depending on platform, a variety of different video and audio output methods are supported. Mpv has an OpenGL, Vulkan, and D3D11 based video output that is capable of many features loved by videophiles, such as video scaling with popular high quality algorithms, color management, frame timing, interpolation, HDR, and more. While mpv strives for minimalism and provides no real GUI, it has a small controller on top of the video for basic control. Mpv can leverage most hardware decoding APIs on all platforms. Hardware decoding can be enabled at runtime on demand. Powerful scripting capabilities can make the player do almost anything. There is a large selection of user scripts on the wiki. A straightforward C API was designed from the ground up to make mpv usable as a library and facilitate easy integration into other applications. --------------------------------------------------------------------------------Update Information: FFmpeg 6.0 upgrade. ---- update to 111.0.5563.64. Fixes the following security issues: CVE-2023-0927 CVE-2023-0928 CVE-2023-0929 CVE-2023-0930 CVE-2023-0931 CVE-2023-0932 CVE-2023-0933 CVE-2023-0941 CVE-2023-1213 CVE-2023-1214 CVE-2023-1215 CVE-2023-1216 CVE-2023-1217 CVE-2023-1218 CVE-2023-1219 CVE-2023-1220 CVE-2023-1221 CVE-2023-1222 CVE-2023-1223 CVE-2023-1224 CVE-2023-1225 CVE-2023-1226 CVE-2023-1227 --------------------------------------------------------------------------------ChangeLog: * Sun Mar 12 2023 Neal Gompa - 0.35.1-3 - Rebuild for ffmpeg 6.0 --------------------------------------------------------------------------------References: [ 1 ] Bug #1944122 - notcurses-2.3.17 is available https://bugzilla.redhat.com/show_bug.cgi?id=1944122 [ 2 ] Bug #2022640 - notcurses-2.4.9 is available https://bugzilla.redhat.com/show_bug.cgi?id=2022640 [ 3 ] Bug #2028587 - notcurses-3.0.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=2028587 [ 4 ] Bug #2045133 - notcurses: FTBFS in Fedora rawhide/f36 https://bugzilla.redhat.com/show_bug.cgi?id=2045133 [ 5 ] Bug #2053373 - notcurses-3.0.6 is available https://bugzilla.redhat.com/show_bug.cgi?id=2053373 [ 6 ] Bug #2172934 - CVE-2023-0927 CVE-2023-0928 CVE-2023-0929 CVE-2023-0930 CVE-2023-0931 CVE-2023-0932 CVE-2023-0933 CVE-2023-0941 chromium: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2172934 [ 7 ] Bug #2173846 - ffmpeg-6.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2173846 [ 8 ] Bug #2174875 - k3b-22.12.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=2174875 [ 9 ] Bug #2176135 - mlt-7.14.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2176135 [ 10 ] Bug #2176519 - CVE-2023-1213 CVE-2023-1214 CVE-2023-1215 CVE-2023-1216 CVE-2023-1217 CVE-2023-1218 CVE-2023-1219 CVE-2023-1220 CVE-2023-1221 CVE-2023-1222 CVE-2023-1223 CVE-2023-1224 CVE-2023-1225 CVE-2023-1226 CVE-2023-1227 ... chromium:various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2176519 [ 11 ] Bug #2176520 - CVE-2023-1213 CVE-2023-1214 CVE-2023-1215 CVE-2023-1216 CVE-2023-1217 CVE-2023-1218 CVE-2023-1219 CVE-2023-1220 CVE-2023-1221 CVE-2023-1222 CVE-2023-1223 CVE-2023-1224 CVE-2023-1225 CVE-2023-1226 CVE-2023-1227 ... chromium: various flaws [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2176520 [ 12 ] Bug #2177300 - retroarch-1.15.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2177300 [ 13 ] Bug #2177550 - nv-codec-headers-12.0.16.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2177550 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-a5e10b188a' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
FFmpeg 6.0 upgrade. ---- update to 111.0.5563.64. Fixes the following security issues: CVE-2023-0927 CVE-2023-0928 CVE-2023-0929 CVE-2023-0930 CVE-2023-0931 CVE-2023-0932 CVE-2023-0933 CVE-2023-0941 CVE-2023-1213 CVE-2023-1214 CVE-2023-1215 CVE-2023-1216 CVE-2023-1217 CVE-2023-1218 CVE-2023-1219 CVE-2023-1220 CVE-2023-1221 CVE-2023-1222 CVE-2023-1223. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-a5e10b188a 2023-03-14 00:16:44.047436 --------------------------------------------------------------------------------Name : haruna Product : Fedora 38 Version : 0.10.3 Release : 3.fc38 URL : Summary : Open source video player built with Qt/QML and libmpv Description : Open source video player built with Qt/QML and libmpv. Features: + play online videos, through youtube-dl; + supports youtube playlists; + toggle playlist with mouse-over, playlist overlays the video; + auto skip chapter containing certain words; + configurable shortcuts and mouse buttons; + quick jump to next chapter by middle click on progress bar. --------------------------------------------------------------------------------Update Information: FFmpeg 6.0 upgrade. ---- update to 111.0.5563.64. Fixes the following security issues: CVE-2023-0927 CVE-2023-0928 CVE-2023-0929 CVE-2023-0930 CVE-2023-0931 CVE-2023-0932 CVE-2023-0933 CVE-2023-0941 CVE-2023-1213 CVE-2023-1214 CVE-2023-1215 CVE-2023-1216 CVE-2023-1217 CVE-2023-1218 CVE-2023-1219 CVE-2023-1220 CVE-2023-1221 CVE-2023-1222 CVE-2023-1223 CVE-2023-1224 CVE-2023-1225 CVE-2023-1226 CVE-2023-1227 --------------------------------------------------------------------------------ChangeLog: * Sun Mar 12 2023 Neal Gompa - 0.10.3-3 - Rebuild for ffmpeg 6.0 * Wed Feb 22 2023 Yaroslav Sidlovsky - 0.10.3-2 - fix: require kf5-kirigami2 --------------------------------------------------------------------------------References: [ 1 ] Bug #1944122- notcurses-2.3.17 is available https://bugzilla.redhat.com/show_bug.cgi?id=1944122 [ 2 ] Bug #2022640 - notcurses-2.4.9 is available https://bugzilla.redhat.com/show_bug.cgi?id=2022640 [ 3 ] Bug #2028587 - notcurses-3.0.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=2028587 [ 4 ] Bug #2045133 - notcurses: FTBFS in Fedora rawhide/f36 https://bugzilla.redhat.com/show_bug.cgi?id=2045133 [ 5 ] Bug #2053373 - notcurses-3.0.6 is available https://bugzilla.redhat.com/show_bug.cgi?id=2053373 [ 6 ] Bug #2172934 - CVE-2023-0927 CVE-2023-0928 CVE-2023-0929 CVE-2023-0930 CVE-2023-0931 CVE-2023-0932 CVE-2023-0933 CVE-2023-0941 chromium: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2172934 [ 7 ] Bug #2173846 - ffmpeg-6.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2173846 [ 8 ] Bug #2174875 - k3b-22.12.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=2174875 [ 9 ] Bug #2176135 - mlt-7.14.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2176135 [ 10 ] Bug #2176519 - CVE-2023-1213 CVE-2023-1214 CVE-2023-1215 CVE-2023-1216 CVE-2023-1217 CVE-2023-1218 CVE-2023-1219 CVE-2023-1220 CVE-2023-1221 CVE-2023-1222 CVE-2023-1223 CVE-2023-1224 CVE-2023-1225 CVE-2023-1226 CVE-2023-1227 ... chromium: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2176519 [ 11 ] Bug #2176520 - CVE-2023-1213 CVE-2023-1214 CVE-2023-1215 CVE-2023-1216 CVE-2023-1217 CVE-2023-1218 CVE-2023-1219 CVE-2023-1220 CVE-2023-1221 CVE-2023-1222 CVE-2023-1223 CVE-2023-1224 CVE-2023-1225 CVE-2023-1226 CVE-2023-1227 ... chromium: various flaws [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2176520 [ 12 ] Bug #2177300 - retroarch-1.15.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2177300 [ 13 ] Bug #2177550 - nv-codec-headers-12.0.16.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2177550 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-a5e10b188a' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.