GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Mon Jul 10, 2017 4:26 pm Post subject: [ GLSA 201705-10 ] GStreamer plug-ins |
|
|
Gentoo Linux Security Advisory
Title: GStreamer plug-ins: User-assisted execution of arbitrary code (GLSA 201705-10)
Severity: normal
Exploitable: remote
Date: 2017-05-18
Bug(s): #600142, #601354
ID: 201705-10
Synopsis
Multiple vulnerabilities have been found in various GStreamer
plug-ins, the worst of which could lead to the execution of arbitrary code.
Background
The GStreamer plug-ins provide decoders to the GStreamer open source
media framework.
Affected Packages
Package: media-libs/gst-plugins-bad
Vulnerable: < 1.10.3
Unaffected: >= 1.10.3
Architectures: All supported architectures
Package: media-libs/gst-plugins-good
Vulnerable: < 1.10.3
Unaffected: >= 1.10.3
Architectures: All supported architectures
Package: media-libs/gst-plugins-base
Vulnerable: < 1.10.3
Unaffected: >= 1.10.3
Architectures: All supported architectures
Package: media-libs/gst-plugins-ugly
Vulnerable: < 1.10.3
Unaffected: >= 1.10.3
Architectures: All supported architectures
Description
Multiple vulnerabilities have been discovered in various GStreamer
plug-ins. Please review the CVE identifiers referenced below for details.
Impact
A remote attacker could entice a user or automated system using a
GStreamer plug-in to process a specially crafted file, resulting in the
execution of arbitrary code or a Denial of Service.
Workaround
There is no known workaround at this time.
Resolution
All gst-plugins-bad users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose
">=media-libs/gst-plugins-bad-1.10.3:1.0"
| All gst-plugins-good users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose
">=media-libs/gst-plugins-good-1.10.3:1.0"
| All gst-plugins-base users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose
">=media-libs/gst-plugins-base-1.10.3:1.0"
| All gst-plugins-ugly users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose
">=media-libs/gst-plugins-ugly-1.10.3:1.0"
|
References
CVE-2016-10198
CVE-2016-10199
CVE-2016-9445
CVE-2016-9446
CVE-2016-9447
CVE-2016-9634
CVE-2016-9635
CVE-2016-9636
CVE-2016-9807
CVE-2016-9808
CVE-2016-9809
CVE-2016-9810
CVE-2016-9811
CVE-2016-9812
CVE-2016-9813
CVE-2017-5837
CVE-2017-5838
CVE-2017-5839
CVE-2017-5840
CVE-2017-5841
CVE-2017-5842
CVE-2017-5843
CVE-2017-5844
CVE-2017-5845
CVE-2017-5846
CVE-2017-5847
CVE-2017-5848 |
|