Package "gstreamer1.0-x"
Links
Download "gstreamer1.0-x"
Other versions of "gstreamer1.0-x" in Jammy
Changelog
gst-plugins-base1.0 (1.20.1-1ubuntu0.4) jammy-security; urgency=medium
* SECURITY UPDATE: Multiple security issues
- debian/patches/202412-sec*.patch: backport upstream security fix
commits from 1.24.10.
- CVE-2024-47538, CVE-2024-47541, CVE-2024-47542, CVE-2024-47600,
CVE-2024-47607, CVE-2024-47615, CVE-2024-47835
-- Marc Deslauriers <email address hidden> Tue, 17 Dec 2024 08:24:56 -0500
|
Source diff to previous version |
CVE-2024-47538 |
GStreamer is a library for constructing graphs of media-handling components. A stack-buffer overflow has been detected in the vorbis_handle_identific |
CVE-2024-47541 |
GStreamer is a library for constructing graphs of media-handling components. An OOB-write vulnerability has been identified in the gst_ssa_parse_remo |
CVE-2024-47542 |
GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference has been discovered in the id3v2_read_synch_u |
CVE-2024-47600 |
GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been detected in the format_channel_mask f |
CVE-2024-47607 |
GStreamer is a library for constructing graphs of media-handling components. stack-buffer overflow has been detected in the gst_opus_dec_parse_heade |
CVE-2024-47615 |
GStreamer is a library for constructing graphs of media-handling components. An OOB-Write has been detected in the function gst_parse_vorbis_setup_pa |
CVE-2024-47835 |
GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been detected in the parse_ |
|
gst-plugins-base1.0 (1.20.1-1ubuntu0.2) jammy-security; urgency=medium
* SECURITY UPDATE: Integer overflow
- debian/patches/CVE-2024-4453.patch: Prevent integer overflows and out of bounds reads
when handling undefined tags in gst-libs/gst/tag/gstexiftag.c.
- CVE-2024-4453
-- Leonidas Da Silva Barbosa <email address hidden> Mon, 27 May 2024 11:31:40 -0300
|
Source diff to previous version |
CVE-2024-4453 |
GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary |
|
gst-plugins-base1.0 (1.20.1-1ubuntu0.1) jammy-security; urgency=medium
* SECURITY UPDATE: Heap overwrite in subtitle parsing
- debian/patches/CVE-2023-37328-1.patch: look for the closing > of a
tag after the opening < in gst/subparse/gstsubparse.c.
- debian/patches/CVE-2023-37328-2.patch: skip after the end of a valid
closing tag in gst/subparse/gstsubparse.c.
- CVE-2023-37328
* SECURITY UPDATE: Integer overflow leading to heap overwrite in FLAC
image tag handling
- debian/patches/CVE-2023-37327-2.patch: don't allow image tags with
G_MAXUINT32 length in gst-libs/gst/tag/tags.c.
- CVE-2023-37327
-- Marc Deslauriers <email address hidden> Tue, 01 Aug 2023 08:26:17 -0400
|
|
About
-
Send Feedback to @ubuntu_updates