UbuntuUpdates.org

Package "gir1.2-gst-plugins-base-1.0"

Name: gir1.2-gst-plugins-base-1.0

Description:

GObject introspection data for the GStreamer Plugins Base library

Latest version: 1.24.2-1ubuntu0.2
Release: noble (24.04)
Level: security
Repository: main
Head package: gst-plugins-base1.0
Homepage: https://gstreamer.freedesktop.org

Links


Download "gir1.2-gst-plugins-base-1.0"


Other versions of "gir1.2-gst-plugins-base-1.0" in Noble

Repository Area Version
base main 1.24.2-1
updates main 1.24.2-1ubuntu0.2

Changelog

Version: 1.24.2-1ubuntu0.2 2024-12-18 15:06:57 UTC

  gst-plugins-base1.0 (1.24.2-1ubuntu0.2) noble-security; urgency=medium

  * SECURITY UPDATE: Multiple security issues
    - debian/patches/202412-sec*.patch: backport upstream security fix
      commits from 1.24.10.
    - CVE-2024-47538, CVE-2024-47541, CVE-2024-47542, CVE-2024-47600,
      CVE-2024-47607, CVE-2024-47615, CVE-2024-47835

 -- Marc Deslauriers <email address hidden> Tue, 17 Dec 2024 08:24:56 -0500

Source diff to previous version
CVE-2024-47538 GStreamer is a library for constructing graphs of media-handling components. A stack-buffer overflow has been detected in the vorbis_handle_identific
CVE-2024-47541 GStreamer is a library for constructing graphs of media-handling components. An OOB-write vulnerability has been identified in the gst_ssa_parse_remo
CVE-2024-47542 GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference has been discovered in the id3v2_read_synch_u
CVE-2024-47600 GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been detected in the format_channel_mask f
CVE-2024-47607 GStreamer is a library for constructing graphs of media-handling components. stack-buffer overflow has been detected in the gst_opus_dec_parse_heade
CVE-2024-47615 GStreamer is a library for constructing graphs of media-handling components. An OOB-Write has been detected in the function gst_parse_vorbis_setup_pa
CVE-2024-47835 GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been detected in the parse_

Version: 1.24.2-1ubuntu0.1 2024-05-29 18:08:27 UTC

  gst-plugins-base1.0 (1.24.2-1ubuntu0.1) noble-security; urgency=medium

  * SECURITY UPDATE: Integer overflow
    - debian/patches/CVE-2024-4453.patch: Prevent integer overflows and out of bounds reads
      when handling undefined tags in gst-libs/gst/tag/gstexiftag.c.
    - CVE-2024-4453

 -- Leonidas Da Silva Barbosa <email address hidden> Mon, 27 May 2024 11:13:45 -0300

CVE-2024-4453 GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary



About   -   Send Feedback to @ubuntu_updates