Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2020:1631

Опубликовано: 28 апр. 2020
Источник: rocky
Оценка: Low

Описание

Low: GStreamer, libmad, and SDL security, bug fix, and enhancement update

The GStreamer library provides a streaming media framework based on graphs of media data filters.

The libmad package is an MPEG audio decoder capable of 24-bit output.

Simple DirectMedia Layer (SDL) is a cross-platform multimedia library designed to provide fast access to the graphics frame buffer and audio device.

Security Fix(es):

  • libmad: Double-free in the mad_decoder_run() function (CVE-2018-7263)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 8.2 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
gstreamer1x86_642.el8gstreamer1-1.16.1-2.el8.x86_64.rpm
gstreamer1-develx86_642.el8gstreamer1-devel-1.16.1-2.el8.x86_64.rpm
gstreamer1-plugins-bad-freex86_641.el8gstreamer1-plugins-bad-free-1.16.1-1.el8.x86_64.rpm
gstreamer1-plugins-ugly-freex86_641.el8gstreamer1-plugins-ugly-free-1.16.1-1.el8.x86_64.rpm
libmadx86_6425.el8libmad-0.15.1b-25.el8.x86_64.rpm
orcx86_643.el8orc-0.4.28-3.el8.x86_64.rpm
orc-compilerx86_643.el8orc-compiler-0.4.28-3.el8.x86_64.rpm
orc-develx86_643.el8orc-devel-0.4.28-3.el8.x86_64.rpm

Показывать по

Связанные CVE

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 7 лет назад

The mad_decoder_run() function in decoder.c in Underbit libmad through 0.15.1b allows remote attackers to cause a denial of service (SIGABRT because of double free or corruption) or possibly have unspecified other impact via a crafted file. NOTE: this may overlap CVE-2017-11552.

CVSS3: 3.3
redhat
больше 7 лет назад

The mad_decoder_run() function in decoder.c in Underbit libmad through 0.15.1b allows remote attackers to cause a denial of service (SIGABRT because of double free or corruption) or possibly have unspecified other impact via a crafted file. NOTE: this may overlap CVE-2017-11552.

CVSS3: 9.8
nvd
больше 7 лет назад

The mad_decoder_run() function in decoder.c in Underbit libmad through 0.15.1b allows remote attackers to cause a denial of service (SIGABRT because of double free or corruption) or possibly have unspecified other impact via a crafted file. NOTE: this may overlap CVE-2017-11552.

CVSS3: 9.8
msrc
3 месяца назад

Описание отсутствует

CVSS3: 9.8
debian
больше 7 лет назад

The mad_decoder_run() function in decoder.c in Underbit libmad through ...