You are here
Home > Preporuke > Sigurnosni nedostaci GStreamer dodataka

Sigurnosni nedostaci GStreamer dodataka

==========================================================================
Ubuntu Security Notice USN-3244-1
March 27, 2017

gst-plugins-base0.10, gst-plugins-base1.0 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 16.10
– Ubuntu 16.04 LTS
– Ubuntu 14.04 LTS
– Ubuntu 12.04 LTS

Summary:

GStreamer Base Plugins could be made to crash if it opened a specially
crafted file.

Software Description:
– gst-plugins-base1.0: GStreamer Plugins
– gst-plugins-base0.10: GStreamer Plugins

Details:

Hanno Böck discovered that GStreamer Base Plugins did not correctly handle
certain malformed media files. If a user were tricked into opening a
crafted media file with a GStreamer application, an attacker could cause a
denial of service via application crash.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.10:
gstreamer1.0-plugins-base 1.8.3-1ubuntu1.1

Ubuntu 16.04 LTS:
gstreamer1.0-plugins-base 1.8.3-1ubuntu0.2

Ubuntu 14.04 LTS:
gstreamer0.10-plugins-base 0.10.36-1.1ubuntu2.1
gstreamer1.0-plugins-base 1.2.4-1~ubuntu2.1

Ubuntu 12.04 LTS:
gstreamer0.10-plugins-base 0.10.36-1ubuntu0.2

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-3244-1
CVE-2016-9811, CVE-2017-5837, CVE-2017-5839, CVE-2017-5842,
CVE-2017-5844

Package Information:
https://launchpad.net/ubuntu/+source/gst-plugins-base1.0/1.8.3-1ubuntu1.1
https://launchpad.net/ubuntu/+source/gst-plugins-base1.0/1.8.3-1ubuntu0.2
https://launchpad.net/ubuntu/+source/gst-plugins-base0.10/0.10.36-1.1ubuntu2.1
https://launchpad.net/ubuntu/+source/gst-plugins-base1.0/1.2.4-1~ubuntu2.1
https://launchpad.net/ubuntu/+source/gst-plugins-base0.10/0.10.36-1ubuntu0.2

—–BEGIN PGP SIGNATURE—–
Version: GnuPG v2

iQIcBAEBCgAGBQJY2VY7AAoJEGVp2FWnRL6TRscP/26XYkQQowhj5Z1yp7Qpk4BU
xFJnbBwkzUPxYGZDyXCar43w+m9UWnVef5ucqtlnl72SvlWOkbfh+35ZtGH4UFIh
g+juMhjHiDySTrPJphzRzLf4Hsm84TcjrQ1B+8o7ProNeyxroaep1VRLLkeJ3pay
TU+oQYoTVU394eM0pbSEFUvtNmzFKs6LJnEHqckk0hD7kJ2ZpxOoedk1eY8kjVbu
7TBkMlOjoUrudPhsj6wau97+rJg7rjAKQ6Lh9q47dH4IC4qoc4/KrU4jx9dVXqNF
Pr8/pMpccgZlxRiNjmGruVVX+KLLnv9CDioH2k2NRx8tuxVAVZO1T4lDO8XXSbry
qJjhNO7Sw+RzK47h5QGUcWl2YNqonY//JIFn0rW/lN6folGygUM1rZhAuDG+P6n1
2E4uYWBada6zlPpPOBhafkfVyGlJcIbDAbLAdPw010YRyNAJWBgaMx2IlBtf3R8I
g8ntoorgpAe9kt0cN2kS/SOqd0Mv66kGhHOqlZzWezeBbvQcAs3zW3izilKrb1mB
UfQw5/L65qkJOleo3TGSoBzDSgT6hAtmHCwFGwxGNCfHtX/v4yY7Zoa4nS3f85eL
cbElAUx7Cp0iJaZcaJKONW5j+k4lOPMkH6tje4ngqeNHd4/3oFP0m4Kh+mWDR6r+
lw8vpAfNpiEgBIKIZ9MJ
=HGN4
—–END PGP SIGNATURE—–

ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

==========================================================================
Ubuntu Security Notice USN-3245-1
March 27, 2017

gst-plugins-good0.10, gst-plugins-good1.0 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 16.10
– Ubuntu 16.04 LTS
– Ubuntu 14.04 LTS
– Ubuntu 12.04 LTS

Summary:

GStreamer Good Plugins could be made to crash if it opened a specially
crafted file.

Software Description:
– gst-plugins-good1.0: GStreamer plugins
– gst-plugins-good0.10: GStreamer plugins

Details:

Hanno Böck discovered that GStreamer Good Plugins did not correctly handle
certain malformed media files. If a user were tricked into opening a
crafted media file with a GStreamer application, an attacker could cause a
denial of service via application crash.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.10:
gstreamer1.0-plugins-good 1.8.3-1ubuntu1.3

Ubuntu 16.04 LTS:
gstreamer1.0-plugins-good 1.8.3-1ubuntu0.4

Ubuntu 14.04 LTS:
gstreamer0.10-plugins-good 0.10.31-3+nmu1ubuntu5.3
gstreamer1.0-plugins-good 1.2.4-1~ubuntu1.4

Ubuntu 12.04 LTS:
gstreamer0.10-plugins-good 0.10.31-1ubuntu1.5

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-3245-1
CVE-2016-10198, CVE-2016-10199, CVE-2017-5840, CVE-2017-5841,
CVE-2017-5845

Package Information:
https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.8.3-1ubuntu1.3
https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.8.3-1ubuntu0.4
https://launchpad.net/ubuntu/+source/gst-plugins-good0.10/0.10.31-3+nmu1ubuntu5.3
https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.2.4-1~ubuntu1.4
https://launchpad.net/ubuntu/+source/gst-plugins-good0.10/0.10.31-1ubuntu1.5

—–BEGIN PGP SIGNATURE—–
Version: GnuPG v2

iQIcBAEBCgAGBQJY2VZKAAoJEGVp2FWnRL6TYXsQAKHn1YfcdlE3h5t+GGDweNoA
i5kXxQ6+J1YcAK59gbacnSAZzVxATjWReWGqlQGwTqd34NNVOFyzvuf1k9KunIA5
GeeqSgSeUr8QlJRUtYQXsf0aKXgrt0bV7ByEvhqD6jk46D+ZBUVmCsAjY6CSfGok
0kYB9KPqONwAiETmWbf2MT9WbsP0BmH4+MfM9cOt4K/ns4BboJKEqI3UEWTLMeVW
90h6Dn4LlV5avOCyhRDgIjvkLx2MlT6ckMJZqIYK+RN6eW+AIvOhfxGj+w6aXP6W
VG9h46AFP5JyPsRjYmx0BeNpfAJETQXQxC4cj4lJzHtwX9vJV9nWHwoOkvz4U+Ob
ddkbvyZBUVSmbDMHoeg/skrnJHZG6RYVTXsEh4cJeQ6I33PmnoqMRAoR6CLj455x
YJWXF96i9YAtso7XhwM0vz1A6AF3qgCYsfaUlMh/NGRym6J5OJnLNQN1yZUzkTvc
2DUme81I0KVPu2aqH/yGlx22AlGkbNPoelrvReEUjSENoeKVGREPd1etn0NZ9RpA
brXHFOoJAlfLhRoQEaTH50HI0u6kiOriHqsRJEoPVqengUkQmDUt+nd19qOp20Lx
LYvMRj4xXYwnDMrRdbqA9ZewstlMGZbLWAZAdLwsMABW9V4oGQMIIFqbU6vn18Tv
fCZokK7bTPs9MWrDcIy1
=LEhF
—–END PGP SIGNATURE—–

Top
More in Preporuke
Sigurnosni nedostaci GStreamer dodataka

Otkriveni su sigurnosni nedostaci kod nekoliko dodataka unutar multimedijskog razvojnog okruženja GStreamer za Debian uzrokovani neispravnim upravljanjem posebno oblikovanim medijskim...

Close