Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2017:0388-1

Опубликовано: 04 фев. 2017
Источник: suse-cvrf

Описание

Security update for gstreamer-0_10-plugins-bad

This update for gstreamer-0_10-plugins-bad fixes the following issue:

  • CVE-2016-9809: Off by one read in gst_h264_parse_set_caps() (bsc#1013659)

This update was imported from the SUSE:SLE-12-SP2:Update update project.

Список пакетов

openSUSE Leap 42.2
gstreamer-0_10-plugins-bad-0.10.23-27.1
gstreamer-0_10-plugins-bad-32bit-0.10.23-27.1
gstreamer-0_10-plugins-bad-devel-0.10.23-27.1
gstreamer-0_10-plugins-bad-doc-0.10.23-27.1
gstreamer-0_10-plugins-bad-lang-0.10.23-27.1
libgstbasecamerabinsrc-0_10-23-0.10.23-27.1
libgstbasecamerabinsrc-0_10-23-32bit-0.10.23-27.1
libgstbasevideo-0_10-23-0.10.23-27.1
libgstbasevideo-0_10-23-32bit-0.10.23-27.1
libgstcodecparsers-0_10-23-0.10.23-27.1
libgstcodecparsers-0_10-23-32bit-0.10.23-27.1
libgstphotography-0_10-23-0.10.23-27.1
libgstphotography-0_10-23-32bit-0.10.23-27.1
libgstsignalprocessor-0_10-23-0.10.23-27.1
libgstsignalprocessor-0_10-23-32bit-0.10.23-27.1
libgstvdp-0_10-23-0.10.23-27.1
libgstvdp-0_10-23-32bit-0.10.23-27.1

Описание

Off-by-one error in the gst_h264_parse_set_caps function in GStreamer before 1.10.2 allows remote attackers to have unspecified impact via a crafted file, which triggers an out-of-bounds read.


Затронутые продукты
openSUSE Leap 42.2:gstreamer-0_10-plugins-bad-0.10.23-27.1
openSUSE Leap 42.2:gstreamer-0_10-plugins-bad-32bit-0.10.23-27.1
openSUSE Leap 42.2:gstreamer-0_10-plugins-bad-devel-0.10.23-27.1
openSUSE Leap 42.2:gstreamer-0_10-plugins-bad-doc-0.10.23-27.1

Ссылки
Уязвимость openSUSE-SU-2017:0388-1