Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2019:14076-1

Опубликовано: 11 июн. 2019
Источник: suse-cvrf

Описание

Security update for gstreamer-0_10-plugins-base

This update for gstreamer-0_10-plugins-base fixes the following issues:

Security issues fixed:

  • CVE-2017-5837: Fixed a floating point exception in gst_riff_create_audio_caps (bsc#1024076).
  • CVE-2017-5844: Fixed a floating point exception in gst_riff_create_audio_caps (bsc#1024079).
  • CVE-2019-9928: Fixed a heap-based overflow in the rtsp connection parser (bsc#1133375).

Список пакетов

SUSE Linux Enterprise Point of Sale 11 SP3
gstreamer-0_10-plugins-base-0.10.35-5.18.5.1
gstreamer-0_10-plugins-base-doc-0.10.35-5.18.5.1
gstreamer-0_10-plugins-base-lang-0.10.35-5.18.5.1
libgstapp-0_10-0-0.10.35-5.18.5.1
libgstinterfaces-0_10-0-0.10.35-5.18.5.1
SUSE Linux Enterprise Server 11 SP4-LTSS
gstreamer-0_10-plugins-base-0.10.35-5.18.5.1
gstreamer-0_10-plugins-base-32bit-0.10.35-5.18.5.1
gstreamer-0_10-plugins-base-doc-0.10.35-5.18.5.1
gstreamer-0_10-plugins-base-lang-0.10.35-5.18.5.1
libgstapp-0_10-0-0.10.35-5.18.5.1
libgstapp-0_10-0-32bit-0.10.35-5.18.5.1
libgstinterfaces-0_10-0-0.10.35-5.18.5.1
libgstinterfaces-0_10-0-32bit-0.10.35-5.18.5.1

Описание

The gst_riff_create_audio_caps function in gst-libs/gst/riff/riff-media.c in gst-plugins-base in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (floating point exception and crash) via a crafted video file.


Затронутые продукты
SUSE Linux Enterprise Point of Sale 11 SP3:gstreamer-0_10-plugins-base-0.10.35-5.18.5.1
SUSE Linux Enterprise Point of Sale 11 SP3:gstreamer-0_10-plugins-base-doc-0.10.35-5.18.5.1
SUSE Linux Enterprise Point of Sale 11 SP3:gstreamer-0_10-plugins-base-lang-0.10.35-5.18.5.1
SUSE Linux Enterprise Point of Sale 11 SP3:libgstapp-0_10-0-0.10.35-5.18.5.1

Ссылки

Описание

The gst_riff_create_audio_caps function in gst-libs/gst/riff/riff-media.c in gst-plugins-base in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (floating point exception and crash) via a crafted ASF file.


Затронутые продукты
SUSE Linux Enterprise Point of Sale 11 SP3:gstreamer-0_10-plugins-base-0.10.35-5.18.5.1
SUSE Linux Enterprise Point of Sale 11 SP3:gstreamer-0_10-plugins-base-doc-0.10.35-5.18.5.1
SUSE Linux Enterprise Point of Sale 11 SP3:gstreamer-0_10-plugins-base-lang-0.10.35-5.18.5.1
SUSE Linux Enterprise Point of Sale 11 SP3:libgstapp-0_10-0-0.10.35-5.18.5.1

Ссылки

Описание

GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection parser via a crafted response from a server, potentially allowing remote code execution.


Затронутые продукты
SUSE Linux Enterprise Point of Sale 11 SP3:gstreamer-0_10-plugins-base-0.10.35-5.18.5.1
SUSE Linux Enterprise Point of Sale 11 SP3:gstreamer-0_10-plugins-base-doc-0.10.35-5.18.5.1
SUSE Linux Enterprise Point of Sale 11 SP3:gstreamer-0_10-plugins-base-lang-0.10.35-5.18.5.1
SUSE Linux Enterprise Point of Sale 11 SP3:libgstapp-0_10-0-0.10.35-5.18.5.1

Ссылки