Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the execution of arbitrary code if malformed files/streams are processed. CVE-2023-6603 A flaw was found in FFmpeg's HLS playlist parsing. This vulnerability. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4440-1
A reachable assertion in FFmpeg git-master commit N-113007-g8d24a28d06 allows attackers to cause a Denial of Service (DoS) via opening a crafted AAC file. (CVE-2025-22919) A heap buffer overflow vulnerability in FFmpeg before commit 4bf784c allows attackers to trigger a memory corruption via supplying a crafted . MGASA-2025-0085 - Updated ffmpeg packages fix security vulnerabilities Publication date: 02 Mar 2025 URL: https://advisories.mageia.org/MGASA-2025-0085.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-0518, CVE-2025-22919, CVE-2025-22920, CVE-2025-22921, CVE-2025-25473 A reachable assertion in FFmpeg git-master commit N-113007-g8d24a28d06 allows attackers to cause a Denial of Service (DoS) via opening a crafted AAC file. (CVE-2025-22919) A heap buffer overflow vulnerability in FFmpeg before commit 4bf784c allows attackers to trigger a memory corruption via supplying a crafted media file in avformat when processing tile grid group streams. This can lead to a Denial of Service (DoS). (CVE-2025-22920) FFmpeg git-master,N-113007-g8d24a28d06 was discovered to contain a segmentation violation via the component /libavcodec/jpeg2000dec.c. (CVE-2025-22921) FFmpeg git master before commit c08d30 was discovered to contain a NULL pointer dereference via the component libavformat/mov.c. (CVE-2025-25473) References: - https://bugs.mageia.org/show_bug.cgi?id=34054 - - https://www.cve.org/CVERecord?id=CVE-2025-0518 - https://www.cve.org/CVERecord?id=CVE-2025-22919 - https://www.cve.org/CVERecord?id=CVE-2025-22920 - https://www.cve.org/CVERecord?id=CVE-2025-22921 - https://www.cve.org/CVERecord?id=CVE-2025-25473 SRPMS: - 9/core/ffmpeg-5.1.6-1.3.mga9 - 9/tainted/ffmpeg-5.1.6-1.3.mga9.tainted . Enhanced ffmpeg versions address various vulnerabilities in Mageia. Critical notice, examine for specifics.. FFmpeg Security,Mageia Updates,Denial of Service Fixes. . Severity: Critical. LinuxSecurity.com Team
Update to gstreamer-1.24.10, fixes multiple CVEs.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-0a5722a980 2024-12-22 02:00:45.594041+00:00 -------------------------------------------------------------------------------- Name : mingw-gstreamer1 Product : Fedora 41 Version : 1.24.10 Release : 1.fc41 URL : http://gstreamer.freedesktop.org/ Summary : MinGW Windows Streaming-Media Framework Runtime Description : GStreamer is a streaming-media framework, based on graphs of filters which operate on media data. Applications using this library can do anything from real-time sound processing to playing videos, and just about anything else media-related. Its plug-in-based architecture means that new data types or processing capabilities can be added by installing new plug-ins. -------------------------------------------------------------------------------- Update Information: Update to gstreamer-1.24.10, fixes multiple CVEs. -------------------------------------------------------------------------------- ChangeLog: * Fri Dec 6 2024 Sandro Mani - 1.24.10-1 - Update to 1.24.10 * Tue Nov 5 2024 Sandro Mani - 1.24.9-1 - Update to 1.24.9 * Mon Sep 23 2024 Sandro Mani - 1.24.8-1 - Update to 1.24.8 * Fri Aug 23 2024 Sandro Mani - 1.24.7-1 - Update to 1.24.7 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2331794 - CVE-2024-47542 mingw-gstreamer1-plugins-base: ID3v2 parser out-of-bounds read and NULL-pointer dereference [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331794 [ 2 ] Bug #2331798 - CVE-2024-47540 mingw-gstreamer1-plugins-good: uninitialized stack memory in Matroska/WebM demuxer [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331798 [ 3 ] Bug #2331815 - CVE-2024-47537 mingw-gstreamer1-plugins-good: OOB-write in isomp4/qtdemux.c [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331815 [ 4 ] Bug #2331819 - CVE-2024-47539 mingw-gstreamer1-plugins-good: OOB-write in convert_to_s334_1a [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331819 [ 5 ] Bug #2331829 - CVE-2024-47538 mingw-gstreamer1-plugins-base: GStreamer has a stack-buffer overflow in vorbis_handle_identification_packet [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331829 [ 6 ] Bug #2331865 - CVE-2024-47615 mingw-gstreamer1-plugins-base: out-of-bounds write in Ogg demuxer [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331865 [ 7 ] Bug #2331875 - CVE-2024-47607 mingw-gstreamer1-plugins-base: stack-buffer overflow in gst_opus_dec_parse_header [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331875 [ 8 ] Bug #2331890 - CVE-2024-47606 mingw-gstreamer1-plugins-good: integer overflows in MP4/MOV demuxer and memory allocator that can lead to out-of-bounds writes [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331890 [ 9 ] Bug #2331894 - CVE-2024-47543 mingw-gstreamer1-plugins-good: OOB-read in qtdemux_parse_container [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331894 [ 10 ] Bug #2331899 - CVE-2024-47541 mingw-gstreamer1-plugins-base: GStreamer has an out-of-bounds write in SSA subtitle parser [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331899 [ 11 ] Bug #2331903 - CVE-2024-47600 mingw-gstreamer1-plugins-base: GStreamer has an OOB-read in format_channel_mask [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331903 [ 12 ] Bug #2331907 - CVE-2024-47774 mingw-gstreamer1-plugins-good: GStreamer has an OOB-read in gst_avi_subtitle_parse_gab2_chunk [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331907 [ 13 ] Bug #2332091 - CVE-2024-47777 mingw-gstreamer1-plugins-good: OOB-read in gst_wavparse_smpl_chunk [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2332091 [ 14 ] Bug #2332093 -CVE-2024-47835 mingw-gstreamer1-plugins-base: NULL-pointer dereference in LRC subtitle parser [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2332093 [ 15 ] Bug #2332096 - CVE-2024-47778 mingw-gstreamer1-plugins-good: OOB-read in gst_wavparse_adtl_chunk [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2332096 [ 16 ] Bug #2332098 - CVE-2024-47775 mingw-gstreamer1-plugins-good: OOB-read in parse_ds64 [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2332098 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-0a5722a980' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
1.22.7. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-6a4aea6d13 2023-11-19 01:23:27.465357 -------------------------------------------------------------------------------- Name : gstreamer1-plugins-good Product : Fedora 39 Version : 1.22.7 Release : 1.fc39 URL : https://gstreamer.freedesktop.org/ Summary : GStreamer plugins with good code and licensing Description : GStreamer is a streaming media framework, based on graphs of filters which operate on media data. Applications using this library can do anything from real-time sound processing to playing videos, and just about anything else media-related. Its plugin-based architecture means that new data types or processing capabilities can be added simply by installing new plugins. GStreamer Good Plugins is a collection of well-supported plugins of good quality and under the LGPL license. -------------------------------------------------------------------------------- Update Information: 1.22.7 -------------------------------------------------------------------------------- ChangeLog: * Tue Nov 14 2023 Gwyn Ciesla - 1.22.7-1 - 1.22.7 * Fri Oct 13 2023 Jan Grulich - 1.22.5-3 - Rebuild (qt6) * Thu Oct 5 2023 Jan Grulich - 1.22.5-2 - Rebuild (qt6) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2250248 - CVE-2023-44429 gstreamer1-plugins-bad-free: gstreamer: AV1 codec parser buffer overflow [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2250248 [ 2 ] Bug #2250250 - CVE-2023-44446 gstreamer1-plugins-bad-free: gstreamer: MXF demuxer use-after-free vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2250250 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisoryFEDORA-2023-6a4aea6d13' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
1.22.7. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-6a4aea6d13 2023-11-19 01:23:27.465357 -------------------------------------------------------------------------------- Name : gstreamer1-plugin-libav Product : Fedora 39 Version : 1.22.7 Release : 1.fc39 URL : https://gstreamer.freedesktop.org/ Summary : GStreamer FFmpeg/LibAV plugin Description : GStreamer is a streaming media framework, based on graphs of filters which operate on media data. Applications using this library can do anything from real-time sound processing to playing videos, and just about anything else media-related. Its plugin-based architecture means that new data types or processing capabilities can be added simply by installing new plugins. This package provides FFmpeg/LibAV GStreamer plugin. -------------------------------------------------------------------------------- Update Information: 1.22.7 -------------------------------------------------------------------------------- ChangeLog: * Tue Nov 14 2023 Gwyn Ciesla - 1.22.7-1 - 1.22.7 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2250248 - CVE-2023-44429 gstreamer1-plugins-bad-free: gstreamer: AV1 codec parser buffer overflow [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2250248 [ 2 ] Bug #2250250 - CVE-2023-44446 gstreamer1-plugins-bad-free: gstreamer: MXF demuxer use-after-free vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2250250 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-6a4aea6d13' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora ProjectGPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
The following vulnerabilities have been discovered in the WPE WebKit web engine: CVE-2022-22677 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5183-1
Get the latest Linux and open source security news straight to your inbox.