Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [SECURITY] [DSA 5444-1] gst-plugins-bad1.0 security update

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [SECURITY] [DSA 5444-1] gst-plugins-bad1.0 security update


Chronologisch Thread  
  • From: Moritz Muehlenhoff <jmm AT debian.org>
  • To: debian-security-announce AT lists.debian.org
  • Subject: [IT-SecNots] [SECURITY] [DSA 5444-1] gst-plugins-bad1.0 security update
  • Date: Sun, 2 Jul 2023 08:44:50 +0000
  • Authentication-results: mail.piratenpartei.de; dkim=none; spf=none (mail.piratenpartei.de: domain of "bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org" has no SPF policy when checking 82.195.75.100) smtp.mailfrom="bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org"; dmarc=none
  • List-archive: https://lists.debian.org/msgid-search/ZKE5Agw5MC7Bj0Co AT seger.debian.org
  • List-id: <debian-security-announce.lists.debian.org>
  • List-url: <http://lists.debian.org/debian-security-announce/>
  • Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Content-Type:MIME-Version:Message-ID:Subject:To:From:Date :Reply-To:Cc:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=m9xsF094s/rA0+2IxTwc4LiU5cGc+jqUM/HDWAbTYCs=; b=bT LNfb987KfNEbw82w1CDCkNS70nUONmVvUcER5/icIgFmtM/P5wpsqXO2RDkzQu6vWWk58x2YaLqYe AZ19Hk+zvxEnBgSFxPmubZvucFvbi7veto7chmd8lM8HFjsSr/PXdSiOWQcKN69BY4GbmFKLWSpOV doFR5z5OXEQMFb77K9JcGaYfxI5WHaPmc5XQkqAQJJRk6FTdjI7g2D2N+r+LLB6vnkU8oCOfu9Wbm puai6udBgHcUU/imXNzQhSgKZgQihxP+kACUUE1H9f+rPlVCK54aHHsX+N6m35utbu/EeoEH1+reZ iiA0eAuxsQhYrr7yYgg91Zbv3HEMimvg==;
  • Old-return-path: <jmm AT seger.debian.org>
  • Priority: urgent
  • Resent-date: Sun, 2 Jul 2023 08:45:17 +0000 (UTC)
  • Resent-from: debian-security-announce AT lists.debian.org
  • Resent-message-id: <b4-5QqW-1WL.A.jwF.dkTokB@bendel>
  • Resent-sender: debian-security-announce-request AT lists.debian.org

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-5444-1 security AT debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
July 02, 2023 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : gst-plugins-bad1.0
CVE ID : not yet available

Multiple multiple vulnerabilities were discovered in plugins for the
GStreamer media framework and its codecs and demuxers, which may result
in denial of service or potentially the execution of arbitrary code if
a malformed media file is opened.

For the oldstable distribution (bullseye), this problem has been fixed
in version 1.18.4-3+deb11u1.

For the stable distribution (bookworm), this problem has been fixed in
version 1.22.0-4+deb12u1.

We recommend that you upgrade your gst-plugins-bad1.0 packages.

For the detailed security status of gst-plugins-bad1.0 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/gst-plugins-bad1.0

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmShHBMACgkQEMKTtsN8
TjZhzA//Vucdiu2M/ZA/CUM+5ZQvB9HotGO+WYpirqGMUbqjzWhiKJ9WYv/aLUQR
o1ZAFptb6cpgnITkcvKQMtcy/GbTPegTLJC1VpgFOD80vtyKlilBaHep+v8YIkgT
3E1xlbRTkr7t5ZADbAD5JsiJHpi9Qb79CoIa+iK3PzCqoSIGBHtpCUIFLOUeloaX
LbzdyDh84UBqaZLFlVC6VonifkiVU6zIGwgL20yein2UAo/YIH3tB25TP9hjD/LA
1ZG/b7qUKVLS7QW4I/0rTBhZDIB/a9dFuaxImpAXjYWAs+L5tC1jmgFFxZWsYISf
Gz6GPkdKGZdKUr3tyricVTKBquQfe3S8vtY/yxBKEZ2mEDnWBHbah3/4aov8+31M
Ipurh58m9TRkXuLp9f84851YW4AQd/IWoTrO3nxlmpIsY+ePRBQvqZhGrJU3/ERv
rxmX7h/76sXHVA9+urzxc6+FbBWP8Qkk7hXaFr591Sriq3SfGXO1xECdBwWbVRxi
/qOKpKRq0dDB4I3OPV0uXbBfjYIZG/n1C9LeIvO+t76vGL9EXYBVMbCqYgtfKwEH
cmjHWYuF73TGvppXUkOFRj/5VsGVw2Gdka8lKRHLzIT1Qpr19CdyCIEX+bn1RHJC
TgMEvJ0+6MjNSnkEYEZ6JOepcMf6tUTPscS25VNweEfv6/dVbBY=
=yu1K
-----END PGP SIGNATURE-----



  • [IT-SecNots] [SECURITY] [DSA 5444-1] gst-plugins-bad1.0 security update, Moritz Muehlenhoff, 02.07.2023

Archiv bereitgestellt durch MHonArc 2.6.24.

Seitenanfang