Mehrere Probleme in gst-plugins-bad1.0
ID: | DSA-3818-1 |
Distribution: | Debian |
Plattformen: | Debian sid, Debian jessie |
Datum: | Di, 28. März 2017, 07:25 |
Referenzen: | http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5843
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9813 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9812 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5848 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9809 |
Applikationen: | GStreamer |
Originalnachricht |
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3818-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff March 27, 2017 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : gst-plugins-bad1.0 CVE ID : CVE-2016-9809 CVE-2016-9812 CVE-2016-9813 CVE-2017-5843 CVE-2017-5848 Hanno Boeck discovered multiple vulnerabilities in the GStreamer media framework and its codecs and demuxers, which may result in denial of service or the execution of arbitrary code if a malformed media file is opened. For the stable distribution (jessie), these problems have been fixed in version 1.4.4-2.1+deb8u2. For the upcoming stable distribution (stretch), these problems have been fixed in version 1.10.4-1. For the unstable distribution (sid), these problems have been fixed in version 1.10.4-1. We recommend that you upgrade your gst-plugins-bad1.0 packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAljZeUgACgkQEMKTtsN8 TjYdVRAAp1cFElIuKRDf5hbwgO08655Q/NCLstMBCh6E4U//DemhLbTiWJ94YbpG C+LPzZff39G4z8B2uLOp8fnMnIvQF480xsAbYIGieg+UeuS9SPP4BbOeU0DAPgf7 5ufi+HVvdZ1F6a5JYW6FZ2v9xwhd8FHuZ46u+bEWE6GDjdEcJelSrGudV6KmOyyI u6toH8KtPXQpHgs+yDdvIUK0q+5dYss9jlUGzZ7jTgH6Nywd36sQuxH8f8vDP8w9 Qi36wUvrv9Tz1vngmaUWKUegDkDYLErQsKkqSHaGwuzskypUqlC80Wket9m5uDCw eNI1FD+YeO67ruZz4MyDSht9Q64TML20tfJpxoATumXuZgDCpFwtC4fj9rR/xuh7 mSecfMSqza5zTLXCh/5cBNp1EW7TXLVWYi7WZ0W2u0//B42jhGJkKH0Aw3GhzHF/ xcM/W5lsDeCxOzydje7vcR3zgxuU8DwDvFie5Dq9tu5+ZRCbgC8Nd8Yub+yShGIP eMjQ9CxQEdE3Rm1pUJkBVHr3Vdm+SJ8rB+ushDjlMzE4mEsQZRajpFOLEV3Mqm9Z nYu1G3ucggGvBsbsykcnr9xjX04uZVtYrPVCTg0L4fwIAMScjR/nlqdHMniSN+HZ TFF4K0Z5flUuME7ws1HIFKORYTeGqejNT/tTaoVrwQvKtW2aS/4= =H1vE -----END PGP SIGNATURE----- |