MGASA-2017-0348
Dashboard / Vulnerabilities / MGASA-2017-0348
MGASA-2017-0348
Summary: Updated gstreamer0.10-plugins-good and gstreamer1.0-plugins-good packages fix security vulnerabilities
Details: A crafted AAC audio file could have caused an invalid read and thus corruption or denial of service (CVE-2016-10198). A crafted mp4 file could have caused an invalid read and thus corruption or denial of service (CVE-2016-10199). A crafted AVI file could have caused an invalid read and thus corruption or denial of service (CVE-2017-5840). A crafted AVI file with metadata tag entries (ncdt) could have caused invalid read access and thus corruption or denial of service (CVE-2017-5841). A crafted AVI file could have caused an invalid read access resulting in denial of service (CVE-2017-5845). Note that GStreamer 0.10 was only affected by CVE-2016-10198 and CVE-2017-5840.
References: https://advisories.mageia.org/MGASA-2017-0348.html, https://bugs.mageia.org/show_bug.cgi?id=20237, http://openwall.com/lists/oss-security/2017/02/02/9, https://lists.opensuse.org/opensuse-updates/2017-04/msg00073.html, https://lwn.net/Alerts/714997/
Affected packages
Package
Name: gstreamer0.10-plugins-good
Purl: pkg:rpm/mageia/gstreamer0.10-plugins-good?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
