Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 615
Alerts This Week
Warning Icon 1 615

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 28 articles for you...
89

Fedora 41: FEDORA-2024-0a5722a980 critical: mingw-gstreamer1 security fix

Update to gstreamer-1.24.10, fixes multiple CVEs.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-0a5722a980 2024-12-22 02:00:45.594041+00:00 -------------------------------------------------------------------------------- Name : mingw-gstreamer1 Product : Fedora 41 Version : 1.24.10 Release : 1.fc41 URL : http://gstreamer.freedesktop.org/ Summary : MinGW Windows Streaming-Media Framework Runtime Description : GStreamer is a streaming-media framework, based on graphs of filters which operate on media data. Applications using this library can do anything from real-time sound processing to playing videos, and just about anything else media-related. Its plug-in-based architecture means that new data types or processing capabilities can be added by installing new plug-ins. -------------------------------------------------------------------------------- Update Information: Update to gstreamer-1.24.10, fixes multiple CVEs. -------------------------------------------------------------------------------- ChangeLog: * Fri Dec 6 2024 Sandro Mani - 1.24.10-1 - Update to 1.24.10 * Tue Nov 5 2024 Sandro Mani - 1.24.9-1 - Update to 1.24.9 * Mon Sep 23 2024 Sandro Mani - 1.24.8-1 - Update to 1.24.8 * Fri Aug 23 2024 Sandro Mani - 1.24.7-1 - Update to 1.24.7 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2331794 - CVE-2024-47542 mingw-gstreamer1-plugins-base: ID3v2 parser out-of-bounds read and NULL-pointer dereference [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331794 [ 2 ] Bug #2331798 - CVE-2024-47540 mingw-gstreamer1-plugins-good: uninitialized stack memory in Matroska/WebM demuxer [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331798 [ 3 ] Bug #2331815 - CVE-2024-47537 mingw-gstreamer1-plugins-good: OOB-write in isomp4/qtdemux.c [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331815 [ 4 ] Bug #2331819 - CVE-2024-47539 mingw-gstreamer1-plugins-good: OOB-write in convert_to_s334_1a [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331819 [ 5 ] Bug #2331829 - CVE-2024-47538 mingw-gstreamer1-plugins-base: GStreamer has a stack-buffer overflow in vorbis_handle_identification_packet [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331829 [ 6 ] Bug #2331865 - CVE-2024-47615 mingw-gstreamer1-plugins-base: out-of-bounds write in Ogg demuxer [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331865 [ 7 ] Bug #2331875 - CVE-2024-47607 mingw-gstreamer1-plugins-base: stack-buffer overflow in gst_opus_dec_parse_header [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331875 [ 8 ] Bug #2331890 - CVE-2024-47606 mingw-gstreamer1-plugins-good: integer overflows in MP4/MOV demuxer and memory allocator that can lead to out-of-bounds writes [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331890 [ 9 ] Bug #2331894 - CVE-2024-47543 mingw-gstreamer1-plugins-good: OOB-read in qtdemux_parse_container [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331894 [ 10 ] Bug #2331899 - CVE-2024-47541 mingw-gstreamer1-plugins-base: GStreamer has an out-of-bounds write in SSA subtitle parser [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331899 [ 11 ] Bug #2331903 - CVE-2024-47600 mingw-gstreamer1-plugins-base: GStreamer has an OOB-read in format_channel_mask [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331903 [ 12 ] Bug #2331907 - CVE-2024-47774 mingw-gstreamer1-plugins-good: GStreamer has an OOB-read in gst_avi_subtitle_parse_gab2_chunk [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2331907 [ 13 ] Bug #2332091 - CVE-2024-47777 mingw-gstreamer1-plugins-good: OOB-read in gst_wavparse_smpl_chunk [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2332091 [ 14 ] Bug #2332093 -CVE-2024-47835 mingw-gstreamer1-plugins-base: NULL-pointer dereference in LRC subtitle parser [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2332093 [ 15 ] Bug #2332096 - CVE-2024-47778 mingw-gstreamer1-plugins-good: OOB-read in gst_wavparse_adtl_chunk [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2332096 [ 16 ] Bug #2332098 - CVE-2024-47775 mingw-gstreamer1-plugins-good: OOB-read in parse_ds64 [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2332098 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-0a5722a980' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . The mingw-gstreamer1 1.24.10 release introduces crucial security enhancements for Fedora users, bolstering protection against significant vulnerabilities.. mingw-gstreamer1, Fedora 41, security fixes, streaming media. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 22, 2024 Critical Fedora
217

Oracle Linux 8 ELSA-2024-11299 Critical Advisory: Gstreamer Plugin Updates

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-11299 http://linux.oracle.com/errata/ELSA-2024-11299.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: gstreamer1-plugins-good-1.16.1-5.el8_10.i686.rpm gstreamer1-plugins-good-1.16.1-5.el8_10.x86_64.rpm gstreamer1-plugins-good-gtk-1.16.1-5.el8_10.i686.rpm gstreamer1-plugins-good-gtk-1.16.1-5.el8_10.x86_64.rpm aarch64: gstreamer1-plugins-good-1.16.1-5.el8_10.aarch64.rpm gstreamer1-plugins-good-gtk-1.16.1-5.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//gstreamer1-plugins-good-1.16.1-5.el8_10.src.rpm Related CVEs: CVE-2024-47537 CVE-2024-47539 CVE-2024-47540 CVE-2024-47606 CVE-2024-47613 Description of changes: [1.16.1-5] - CVE-2024-47537, CVE-2024-47539, CVE-2024-47540, CVE-2024-47606, CVE-2024-47613 Resolves: RHEL-70949, RHEL-70962, RHEL-70936, RHEL-71022 Resolves: RHEL-70998 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Recent Oracle Linux releases for gstreamer address several urgent vulnerabilities. For further information, refer to the security notification ELSA-2024-11300.. Oracle Linux Updates, Gstreamer Security, ELSA-2024-11299, Plugin Upgrade, RPM Security Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 19, 2024 Critical Oracle
89

Fedora 40: 2024-2e27372d4c Critical: Deepin Qt Plugins CVE-2024-36048

Qt 5.15.14 bugfix update. Fix CVE-2024-36048. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-2e27372d4c 2024-06-05 01:40:23.602023 -------------------------------------------------------------------------------- Name : deepin-qt5platform-plugins Product : Fedora 40 Version : 5.6.12 Release : 7.fc40 URL : https://github.com/linuxdeepin/qt5platform-plugins Summary : Qt platform integration plugins for Deepin Desktop Environment Description : qt5platform-plugins is the Qt platform integration plugins for Deepin Desktop Environment. -------------------------------------------------------------------------------- Update Information: Qt 5.15.14 bugfix update. Fix CVE-2024-36048 -------------------------------------------------------------------------------- ChangeLog: * Thu May 30 2024 Jan Grulich - 5.6.12-7 - Rebuild (qt5) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2282866 - CVE-2024-36048 qt5-qtnetworkauth: qtnetworkauth: badly seeded PRNG may result in guessable values [epel-8] https://bugzilla.redhat.com/show_bug.cgi?id=2282866 [ 2 ] Bug #2282867 - CVE-2024-36048 qt5-qtnetworkauth: qtnetworkauth: badly seeded PRNG may result in guessable values [fedora-39] https://bugzilla.redhat.com/show_bug.cgi?id=2282867 [ 3 ] Bug #2282869 - CVE-2024-36048 qt5-qtnetworkauth: qtnetworkauth: badly seeded PRNG may result in guessable values [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2282869 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-2e27372d4c' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed withthe Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . A bugfix release for Qt 5.15.14 has been issued for Fedora, correcting vulnerability CVE-2024-36048, improving overall security and operational efficiency.. deepin QT updates,Fedora security,bugfix notification. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 05, 2024 Critical Fedora
89

Fedora 40: FEDORA-2024-129d8ca6fc High Threat: Type Confusion in V8

Change for system JDK from 17 to 21. upstream security release 122.0.6261.94 High CVE-2024-1938: Type Confusion in V8 High CVE-2024-1939: Type Confusion in V8 fixed bug with requires. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-129d8ca6fc 2024-03-07 22:24:39.963937 -------------------------------------------------------------------------------- Name : maven-remote-resources-plugin Product : Fedora 40 Version : 3.1.0 Release : 6.fc40 URL : https://maven.apache.org/plugins/maven-remote-resources-plugin/ Summary : Maven Remote Resources Plugin Description : Process resources packaged in JARs that have been deployed to a remote repository. The primary use case being satisfied is the consistent inclusion of common resources in a large set of projects. Maven projects at Apache use this plug-in to satisfy licensing requirements at Apache where each project much include license and notice files for each release. -------------------------------------------------------------------------------- Update Information: Change for system JDK from 17 to 21. upstream security release 122.0.6261.94 High CVE-2024-1938: Type Confusion in V8 High CVE-2024-1939: Type Confusion in V8 fixed bug with requires Automatic update for lucene-9.9.2-1.fc40. bump java source/target to 1.8, fixes 2266639 -------------------------------------------------------------------------------- ChangeLog: * Sat Mar 2 2024 Jiri Vanek - 3.1.0-6 - Rebuilt for java-21-openjdk as system jdk * Fri Mar 1 2024 Jiri Vanek - 3.1.0-5 - bump of release for for java-21-openjdk as system jdk -------------------------------------------------------------------------------- References: [ 1 ] Bug #2123726 - consoleImageViewer crashes at start https://bugzilla.redhat.com/show_bug.cgi?id=2123726 [ 2 ] Bug #2261062 - directory-maven-plugin: FTBFS in Fedora rawhide/f40 https://bugzilla.redhat.com/show_bug.cgi?id=2261062 [ 3 ] Bug #2266639 - directory-maven-plugin fails to build with java-21-openjdk https://bugzilla.redhat.com/show_bug.cgi?id=2266639 [ 4 ] Bug #2266934 - CVE-2024-1938 chromium: type confusion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2266934 [ 5 ] Bug #2266937 - CVE-2024-1939 chromium: type confusion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2266937 [ 6 ] Bug #2267486 - Include Java 21 as system Java Change in Fedora 40 Beta https://bugzilla.redhat.com/show_bug.cgi?id=2267486 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-129d8ca6fc' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Stay informed about the recent Fedora Update FEDORA-2024-24a1b5d647, which tackles type inconsistency issues in V8 while also upgrading the system's JDK for enhanced performance.. Fedora 40 Update,maven-remote-resources-plugin,type confusion,Java security,upstream release. . LinuxSecurity.com Team

Calendar%202 Mar 07, 2024 Fedora
89

Fedora 38: FEDORA-2023-0984b63b23 Critical: GStreamer Plugin Fix

Update to 1.22.7, fixes CVE-2023-37327, CVE-2023-37328, CVE-2023-37329.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-0984b63b23 2023-12-25 03:36:41.790176 -------------------------------------------------------------------------------- Name : mingw-gstreamer1-plugins-good Product : Fedora 38 Version : 1.22.7 Release : 1.fc38 URL : https://gstreamer.freedesktop.org/ Summary : Cross compiled GStreamer1 plug-ins good Description : GStreamer is a streaming media framework, based on graphs of filters which operate on media data. Applications using this library can do anything from real-time sound processing to playing videos, and just about anything else media-related. Its plugin-based architecture means that new data types or processing capabilities can be added simply by installing new plugins. GStreamer Good Plugins is a collection of well-supported plugins of good quality and under the LGPL license. -------------------------------------------------------------------------------- Update Information: Update to 1.22.7, fixes CVE-2023-37327, CVE-2023-37328, CVE-2023-37329. -------------------------------------------------------------------------------- ChangeLog: * Wed Nov 15 2023 Sandro Mani - 1.22.7-1 - Update to 1.22.7 * Thu Sep 21 2023 Sandro Mani - 1.22.6-1 - Update to 1.22.6 * Sat Jul 29 2023 Sandro Mani - 1.22.5-1 - Update to 1.22.5 * Thu Jul 20 2023 Fedora Release Engineering - 1.22.4-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild * Tue Jul 4 2023 Sandro Mani - 1.22.4-1 - Update to 1.22.4 * Thu May 25 2023 Sandro Mani - 1.22.3-1 - Update to 1.22.3 * Sat Apr 15 2023 Sandro Mani - 1.22.2-1 - Update to 1.22.2 * Sun Mar 19 2023 Sandro Mani - 1.22.1-1 - Update to 1.22.1 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2254680 - CVE-2023-37327mingw-gstreamer1-plugins-good: gstreamer-plugins-good: integer overflow leading to heap overwrite in FLAC image tag handling [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2254680 [ 2 ] Bug #2254682 - CVE-2023-37328 mingw-gstreamer1-plugins-base: gstreamer-plugins-base: heap overwrite in subtitle parsing [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2254682 [ 3 ] Bug #2254684 - CVE-2023-37329 mingw-gstreamer1-plugins-bad-free: gstreamer-plugins-bad: heap overwrite in PGS subtitle overlay decoder [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2254684 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-0984b63b23' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Crucial patches released for mingw-gstreamer components in Fedora 38 addressing memory corruption issues. Stay updated!. Mingw-gstreamer Plugins, Fedora Security Advisories, Heap Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 25, 2023 Critical Fedora
217

Oracle Linux 8 ELSA-2023-7841 critical: GStreamer use-after-free

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-7841 https://linux.oracle.com/errata/ELSA-2023-7841.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: gstreamer1-plugins-bad-free-1.16.1-2.el8_9.i686.rpm gstreamer1-plugins-bad-free-1.16.1-2.el8_9.x86_64.rpm gstreamer1-plugins-bad-free-devel-1.16.1-2.el8_9.i686.rpm gstreamer1-plugins-bad-free-devel-1.16.1-2.el8_9.x86_64.rpm aarch64: gstreamer1-plugins-bad-free-1.16.1-2.el8_9.aarch64.rpm gstreamer1-plugins-bad-free-devel-1.16.1-2.el8_9.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates//gstreamer1-plugins-bad-free-1.16.1-2.el8_9.src.rpm Related CVEs: CVE-2023-44446 Description of changes: [1.16.1-2] - Resolves MXF demuxer use-after-free vulnerability (CVE-2023-44446) _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux 8 has added new RPM packages to address security flaws highlighted in CVE-2023-44446. Discover the main enhancements available now.. Oracle Linux, GStreamer Plugins, Important Updates, Security Management. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 20, 2023 Critical Oracle
217

Oracle Linux 9 ELSA-2023-7766 Moderate: Containernetworking Plugin Update

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-7766 https://linux.oracle.com/errata/ELSA-2023-7766.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: containernetworking-plugins-1.3.0-6.el9_3.x86_64.rpm aarch64: containernetworking-plugins-1.3.0-6.el9_3.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol9/SRPMS-updates//containernetworking-plugins-1.3.0-6.el9_3.src.rpm Related CVEs: CVE-2023-29409 CVE-2023-39318 CVE-2023-39319 CVE-2023-39321 CVE-2023-39322 Description of changes: [1:1.3.0-6] - rebuild for following CVEs: CVE-2023-29409 CVE-2023-39318 CVE-2023-39319 CVE-2023-39321 CVE-2023-39322 - Resolves: #2228743 - Resolves: #2237773 - Resolves: #2237776 - Resolves: #2237777 - Resolves: #2237778 [1:1.3.0-5] - fix path to dhcp service - Resolves: #RHEL-3140 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux 9 updates address critical container networking vulnerabilities, enhancing overall system security.. Oracle Linux Security, Network Plugins Update, ELSA-2023-7766. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 15, 2023 Important Oracle
89

Fedora 39: 2023-6a4aea6d13 Moderate: GStreamer Buffer Overflow

1.22.7. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-6a4aea6d13 2023-11-19 01:23:27.465357 -------------------------------------------------------------------------------- Name : gstreamer1-plugins-ugly-free Product : Fedora 39 Version : 1.22.7 Release : 1.fc39 URL : https://gstreamer.freedesktop.org/ Summary : GStreamer streaming media framework "ugly" plugins Description : GStreamer is a streaming media framework, based on graphs of elements which operate on media data. This package contains plug-ins whose license is not fully compatible with LGPL. -------------------------------------------------------------------------------- Update Information: 1.22.7 -------------------------------------------------------------------------------- ChangeLog: * Tue Nov 14 2023 Gwyn Ciesla - 1.22.7-1 - 1.22.7 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2250248 - CVE-2023-44429 gstreamer1-plugins-bad-free: gstreamer: AV1 codec parser buffer overflow [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2250248 [ 2 ] Bug #2250250 - CVE-2023-44446 gstreamer1-plugins-bad-free: gstreamer: MXF demuxer use-after-free vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2250250 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-6a4aea6d13' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Important update for gstreamer1-plugins-ugly-free is being rolled out, enhancing security and fixing vulnerabilities for Fedora users. Apply it promptly. GStreamer Update,Fedora Security,Plugin Update,Media Framework Risk,Buffer Overflow Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 19, 2023 Important Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200