Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2017:1004-1

Опубликовано: 13 апр. 2017
Источник: suse-cvrf

Описание

Security update for gstreamer-plugins-good

This update for gstreamer-plugins-good fixes the following issues:

  • A crafted aac audio file could have caused an invalid read and thus corruption or denial of service (bsc#1024014, CVE-2016-10198)
  • A crafted mp4 file could have caused an invalid read and thus corruption or denial of service (bsc#1024017, CVE-2016-10199)
  • A crafted avi file could have caused an invalid read and thus corruption or denial of service (bsc#1024034, CVE-2017-5840)

Список пакетов

SUSE Linux Enterprise Desktop 12 SP1
gstreamer-plugins-good-1.2.4-2.9.1
gstreamer-plugins-good-lang-1.2.4-2.9.1
SUSE Linux Enterprise Server 12 SP1
gstreamer-plugins-good-1.2.4-2.9.1
gstreamer-plugins-good-lang-1.2.4-2.9.1
SUSE Linux Enterprise Server for SAP Applications 12 SP1
gstreamer-plugins-good-1.2.4-2.9.1
gstreamer-plugins-good-lang-1.2.4-2.9.1

Описание

The gst_aac_parse_sink_setcaps function in gst/audioparsers/gstaacparse.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted audio file.


Затронутые продукты
SUSE Linux Enterprise Desktop 12 SP1:gstreamer-plugins-good-1.2.4-2.9.1
SUSE Linux Enterprise Desktop 12 SP1:gstreamer-plugins-good-lang-1.2.4-2.9.1
SUSE Linux Enterprise Server 12 SP1:gstreamer-plugins-good-1.2.4-2.9.1
SUSE Linux Enterprise Server 12 SP1:gstreamer-plugins-good-lang-1.2.4-2.9.1

Ссылки

Описание

The qtdemux_tag_add_str_full function in gst/isomp4/qtdemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted tag value.


Затронутые продукты
SUSE Linux Enterprise Desktop 12 SP1:gstreamer-plugins-good-1.2.4-2.9.1
SUSE Linux Enterprise Desktop 12 SP1:gstreamer-plugins-good-lang-1.2.4-2.9.1
SUSE Linux Enterprise Server 12 SP1:gstreamer-plugins-good-1.2.4-2.9.1
SUSE Linux Enterprise Server 12 SP1:gstreamer-plugins-good-lang-1.2.4-2.9.1

Ссылки

Описание

The qtdemux_parse_samples function in gst/isomp4/qtdemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds heap read) via vectors involving the current stts index.


Затронутые продукты
SUSE Linux Enterprise Desktop 12 SP1:gstreamer-plugins-good-1.2.4-2.9.1
SUSE Linux Enterprise Desktop 12 SP1:gstreamer-plugins-good-lang-1.2.4-2.9.1
SUSE Linux Enterprise Server 12 SP1:gstreamer-plugins-good-1.2.4-2.9.1
SUSE Linux Enterprise Server 12 SP1:gstreamer-plugins-good-lang-1.2.4-2.9.1

Ссылки
Уязвимость SUSE-SU-2017:1004-1