MGASA-2017-0320

Source
https://advisories.mageia.org/MGASA-2017-0320.html
Import Source
https://advisories.mageia.org/MGASA-2017-0320.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2017-0320
Related
Published
2017-08-29T20:36:17Z
Modified
2017-08-29T20:18:28Z
Summary
Updated gstreamer0.10-plugins-base and gstreamer1.0-plugins-base packages fix security vulnerabilities
Details

Denial of service in GStreamer base plugins can be caused by floating point exceptions (CVE-2017-5837, CVE-2017-5844), stack overflow (CVE-2017-5839), or out-of-bounds heap read (CVE-2017-5842).

Note that GStreamer 0.10 was only affected by the floating point exceptions.

References
Credits

Affected packages

Mageia:5 / gstreamer0.10-plugins-base

Package

Name
gstreamer0.10-plugins-base
Purl
pkg:rpm/mageia/gstreamer0.10-plugins-base?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.10.36-9.2.mga5

Ecosystem specific

{
    "section": "core"
}

Mageia:5 / gstreamer1.0-plugins-base

Package

Name
gstreamer1.0-plugins-base
Purl
pkg:rpm/mageia/gstreamer1.0-plugins-base?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4.3-2.2.mga5

Ecosystem specific

{
    "section": "core"
}