Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2016:3158-1

Опубликовано: 14 дек. 2016
Источник: suse-cvrf

Описание

Security update for gstreamer-plugins-bad

This update for gstreamer-plugins-bad fixes the following issues:

  • Maliciously crafted VMnc (VMware video) streams (typically contained in .avi files) could cause code execution during decoding or information leaks due to an unitialized buffer (CVE-2016-9445, CVE-2016-9446, boo#1010829).

Список пакетов

openSUSE Leap 42.1
gstreamer-plugins-bad-1.4.5-8.1
gstreamer-plugins-bad-32bit-1.4.5-8.1
gstreamer-plugins-bad-devel-1.4.5-8.1
gstreamer-plugins-bad-doc-1.4.5-8.1
gstreamer-plugins-bad-lang-1.4.5-8.1
libgstbadbase-1_0-0-1.4.5-8.1
libgstbadbase-1_0-0-32bit-1.4.5-8.1
libgstbadvideo-1_0-0-1.4.5-8.1
libgstbadvideo-1_0-0-32bit-1.4.5-8.1
libgstbasecamerabinsrc-1_0-0-1.4.5-8.1
libgstbasecamerabinsrc-1_0-0-32bit-1.4.5-8.1
libgstcodecparsers-1_0-0-1.4.5-8.1
libgstcodecparsers-1_0-0-32bit-1.4.5-8.1
libgstgl-1_0-0-1.4.5-8.1
libgstgl-1_0-0-32bit-1.4.5-8.1
libgstinsertbin-1_0-0-1.4.5-8.1
libgstinsertbin-1_0-0-32bit-1.4.5-8.1
libgstmpegts-1_0-0-1.4.5-8.1
libgstmpegts-1_0-0-32bit-1.4.5-8.1
libgstphotography-1_0-0-1.4.5-8.1
libgstphotography-1_0-0-32bit-1.4.5-8.1
libgsturidownloader-1_0-0-1.4.5-8.1
libgsturidownloader-1_0-0-32bit-1.4.5-8.1
libgstwayland-1_0-0-1.4.5-8.1
libgstwayland-1_0-0-32bit-1.4.5-8.1

Описание

Integer overflow in the vmnc decoder in the gstreamer allows remote attackers to cause a denial of service (crash) via large width and height values, which triggers a buffer overflow.


Затронутые продукты
openSUSE Leap 42.1:gstreamer-plugins-bad-1.4.5-8.1
openSUSE Leap 42.1:gstreamer-plugins-bad-32bit-1.4.5-8.1
openSUSE Leap 42.1:gstreamer-plugins-bad-devel-1.4.5-8.1
openSUSE Leap 42.1:gstreamer-plugins-bad-doc-1.4.5-8.1

Ссылки

Описание

The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated by thumbnailing a simple 1 frame vmnc movie that does not draw to the allocated render canvas.


Затронутые продукты
openSUSE Leap 42.1:gstreamer-plugins-bad-1.4.5-8.1
openSUSE Leap 42.1:gstreamer-plugins-bad-32bit-1.4.5-8.1
openSUSE Leap 42.1:gstreamer-plugins-bad-devel-1.4.5-8.1
openSUSE Leap 42.1:gstreamer-plugins-bad-doc-1.4.5-8.1

Ссылки
Уязвимость openSUSE-SU-2016:3158-1