Advisories ยป MGASA-2018-0012

Updated gstreamer0.10-plugins-bad/gstreamer1.0-plugins-bad packages fix security vulnerability

Publication date: 01 Jan 2018
Modification date: 01 Jan 2018
Type: security
Affected Mageia releases : 5
CVE: CVE-2016-9445 , CVE-2016-9446 , CVE-2016-9447 , CVE-2016-9809 , CVE-2016-9812 , CVE-2016-9813 , CVE-2017-5843 , CVE-2017-5848

Description

Chris Evans discovered that the GStreamer plugin to decode VMware screen
capture files allowed the execution of arbitrary code (CVE-2016-9445,
CVE-2016-9446).

Chris Evans discovered that the GStreamer 0.10 plugin to decode NES Sound
Format files allowed the execution of arbitrary code (CVE-2016-9447).

Hanno Boeck discovered multiple vulnerabilities in the GStreamer media
framework and its codecs and demuxers, which may result in denial of
service or the execution of arbitrary code if a malformed media file is
opened (CVE-2016-9809, CVE-2016-9812, CVE-2016-9813, CVE-2017-5843,
CVE-2017-5848).

The gstreamer0.10-plugins-bad package was affected by CVE-2016-9445,
CVE-2016-9446, CVE-2016-9447, CVE-2016-9809, CVE-2017-5843, and
CVE-2017-5848).

The gstreamer1.0-plugins-bad package was affected by CVE-2016-9445,
CVE-2016-9446, CVE-2016-9809, CVE-2016-9812, CVE-2016-9813, CVE-2017-5843,
and CVE-2017-5848.
                

References

SRPMS

5/core

5/tainted