Описание
Security update for gstreamer-plugins-bad
This update for gstreamer-plugins-bad fixes the following issues:
- Maliciously crafted VMnc (VMware video) streams (typically contained in .avi files) could cause code execution during decoding or information leaks due to an unitialized buffer (CVE-2016-9445, CVE-2016-9446, boo#1010829).
Список пакетов
openSUSE Leap 42.1
gstreamer-plugins-bad-1.4.5-8.1
gstreamer-plugins-bad-32bit-1.4.5-8.1
gstreamer-plugins-bad-devel-1.4.5-8.1
gstreamer-plugins-bad-doc-1.4.5-8.1
gstreamer-plugins-bad-lang-1.4.5-8.1
libgstbadbase-1_0-0-1.4.5-8.1
libgstbadbase-1_0-0-32bit-1.4.5-8.1
libgstbadvideo-1_0-0-1.4.5-8.1
libgstbadvideo-1_0-0-32bit-1.4.5-8.1
libgstbasecamerabinsrc-1_0-0-1.4.5-8.1
libgstbasecamerabinsrc-1_0-0-32bit-1.4.5-8.1
libgstcodecparsers-1_0-0-1.4.5-8.1
libgstcodecparsers-1_0-0-32bit-1.4.5-8.1
libgstgl-1_0-0-1.4.5-8.1
libgstgl-1_0-0-32bit-1.4.5-8.1
libgstinsertbin-1_0-0-1.4.5-8.1
libgstinsertbin-1_0-0-32bit-1.4.5-8.1
libgstmpegts-1_0-0-1.4.5-8.1
libgstmpegts-1_0-0-32bit-1.4.5-8.1
libgstphotography-1_0-0-1.4.5-8.1
libgstphotography-1_0-0-32bit-1.4.5-8.1
libgsturidownloader-1_0-0-1.4.5-8.1
libgsturidownloader-1_0-0-32bit-1.4.5-8.1
libgstwayland-1_0-0-1.4.5-8.1
libgstwayland-1_0-0-32bit-1.4.5-8.1
Ссылки
- E-Mail link for openSUSE-SU-2016:3158-1
- SUSE Security Ratings
Описание
Integer overflow in the vmnc decoder in the gstreamer allows remote attackers to cause a denial of service (crash) via large width and height values, which triggers a buffer overflow.
Затронутые продукты
openSUSE Leap 42.1:gstreamer-plugins-bad-1.4.5-8.1
openSUSE Leap 42.1:gstreamer-plugins-bad-32bit-1.4.5-8.1
openSUSE Leap 42.1:gstreamer-plugins-bad-devel-1.4.5-8.1
openSUSE Leap 42.1:gstreamer-plugins-bad-doc-1.4.5-8.1
Ссылки
- CVE-2016-9445
- SUSE Bug 1010829
Описание
The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated by thumbnailing a simple 1 frame vmnc movie that does not draw to the allocated render canvas.
Затронутые продукты
openSUSE Leap 42.1:gstreamer-plugins-bad-1.4.5-8.1
openSUSE Leap 42.1:gstreamer-plugins-bad-32bit-1.4.5-8.1
openSUSE Leap 42.1:gstreamer-plugins-bad-devel-1.4.5-8.1
openSUSE Leap 42.1:gstreamer-plugins-bad-doc-1.4.5-8.1
Ссылки
- CVE-2016-9446
- SUSE Bug 1010829