ALSA-2020:1631

Source
https://errata.almalinux.org/8/ALSA-2020-1631.html
Import Source
https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2020:1631.json
JSON Data
https://api.osv.dev/v1/vulns/ALSA-2020:1631
Related
Published
2020-04-28T08:58:37Z
Modified
2021-11-12T10:20:55Z
Summary
Low: GStreamer, libmad, and SDL security, bug fix, and enhancement update
Details

The GStreamer library provides a streaming media framework based on graphs of media data filters.

The libmad package is an MPEG audio decoder capable of 24-bit output.

Simple DirectMedia Layer (SDL) is a cross-platform multimedia library designed to provide fast access to the graphics frame buffer and audio device.

Security Fix(es):

  • libmad: Double-free in the maddecoderrun() function (CVE-2018-7263)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.

References

Affected packages

AlmaLinux:8 / SDL2

Package

Name
SDL2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.10-2.el8

AlmaLinux:8 / SDL2-devel

Package

Name
SDL2-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.10-2.el8

AlmaLinux:8 / SDL2-static

Package

Name
SDL2-static

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.10-2.el8

AlmaLinux:8 / gstreamer1

Package

Name
gstreamer1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.16.1-2.el8

AlmaLinux:8 / gstreamer1-devel

Package

Name
gstreamer1-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.16.1-2.el8

AlmaLinux:8 / gstreamer1-plugins-bad-free

Package

Name
gstreamer1-plugins-bad-free

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.16.1-1.el8

AlmaLinux:8 / gstreamer1-plugins-bad-free-devel

Package

Name
gstreamer1-plugins-bad-free-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.16.1-1.el8

AlmaLinux:8 / gstreamer1-plugins-ugly-free

Package

Name
gstreamer1-plugins-ugly-free

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.16.1-1.el8

AlmaLinux:8 / libmad

Package

Name
libmad

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.15.1b-25.el8

AlmaLinux:8 / libmad-devel

Package

Name
libmad-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.15.1b-25.el8

AlmaLinux:8 / orc

Package

Name
orc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.4.28-3.el8

AlmaLinux:8 / orc-compiler

Package

Name
orc-compiler

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.4.28-3.el8

AlmaLinux:8 / orc-devel

Package

Name
orc-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.4.28-3.el8