Security update for gstreamer-plugins-bad
Announcement ID: | SUSE-SU-2016:3296-1 |
---|---|
Rating: | moderate |
References: | |
Cross-References: | |
CVSS scores: |
|
Affected Products: |
|
An update that solves five vulnerabilities can now be installed.
Description:
This update for gstreamer-plugins-bad fixes the following security issues, which would allow attackers able to submit media files for indexing to cause code execution or crashes:
- Check an integer overflow (CVE-2016-9445) and initialize a buffer (CVE-2016-9446) in vmncdec. (bsc#1010829)
- CVE-2016-9809: Ensure codec_data has the right size when reading number of SPS (bsc#1013659).
- CVE-2016-9812: Add more section size checks (bsc#1013678).
- CVE-2016-9813: fix PAT parsing (bsc#1013680).
Patch Instructions:
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
-
SUSE Linux Enterprise Desktop 12 SP2
zypper in -t patch SUSE-SLE-DESKTOP-12-SP2-2016-1933=1
-
SUSE Linux Enterprise Server for the Raspberry Pi 12-SP2
zypper in -t patch SUSE-SLE-RPI-12-SP2-2016-1933=1
-
SUSE Linux Enterprise Software Development Kit 12 12-SP2
zypper in -t patch SUSE-SLE-SDK-12-SP2-2016-1933=1
-
SUSE Linux Enterprise High Performance Computing 12 SP2
zypper in -t patch SUSE-SLE-SERVER-12-SP2-2016-1933=1
-
SUSE Linux Enterprise Server 12 SP2
zypper in -t patch SUSE-SLE-SERVER-12-SP2-2016-1933=1
-
SUSE Linux Enterprise Server for SAP Applications 12 SP2
zypper in -t patch SUSE-SLE-SERVER-12-SP2-2016-1933=1
Package List:
-
SUSE Linux Enterprise Desktop 12 SP2 (x86_64)
- gstreamer-plugins-bad-debuginfo-1.8.3-14.1
- libgstphotography-1_0-0-1.8.3-14.1
- libgstphotography-1_0-0-debuginfo-1.8.3-14.1
- libgstbadbase-1_0-0-debuginfo-1.8.3-14.1
- libgstbasecamerabinsrc-1_0-0-1.8.3-14.1
- libgstcodecparsers-1_0-0-1.8.3-14.1
- libgsturidownloader-1_0-0-1.8.3-14.1
- libgstadaptivedemux-1_0-0-1.8.3-14.1
- libgstbadaudio-1_0-0-debuginfo-1.8.3-14.1
- libgstadaptivedemux-1_0-0-debuginfo-1.8.3-14.1
- libgstbasecamerabinsrc-1_0-0-debuginfo-1.8.3-14.1
- libgstbadvideo-1_0-0-1.8.3-14.1
- libgstmpegts-1_0-0-debuginfo-1.8.3-14.1
- libgstbadvideo-1_0-0-debuginfo-1.8.3-14.1
- libgstgl-1_0-0-1.8.3-14.1
- libgstcodecparsers-1_0-0-debuginfo-1.8.3-14.1
- gstreamer-plugins-bad-debugsource-1.8.3-14.1
- libgstbadaudio-1_0-0-1.8.3-14.1
- libgstgl-1_0-0-debuginfo-1.8.3-14.1
- libgstmpegts-1_0-0-1.8.3-14.1
- gstreamer-plugins-bad-1.8.3-14.1
- libgsturidownloader-1_0-0-debuginfo-1.8.3-14.1
- libgstbadbase-1_0-0-1.8.3-14.1
-
SUSE Linux Enterprise Desktop 12 SP2 (noarch)
- gstreamer-plugins-bad-lang-1.8.3-14.1
-
SUSE Linux Enterprise Server for the Raspberry Pi 12-SP2 (aarch64)
- gstreamer-plugins-bad-debuginfo-1.8.3-14.1
- libgstphotography-1_0-0-1.8.3-14.1
- libgstphotography-1_0-0-debuginfo-1.8.3-14.1
- libgstbadbase-1_0-0-debuginfo-1.8.3-14.1
- libgstbasecamerabinsrc-1_0-0-1.8.3-14.1
- libgstcodecparsers-1_0-0-1.8.3-14.1
- libgsturidownloader-1_0-0-1.8.3-14.1
- libgstadaptivedemux-1_0-0-1.8.3-14.1
- libgstbadaudio-1_0-0-debuginfo-1.8.3-14.1
- libgstadaptivedemux-1_0-0-debuginfo-1.8.3-14.1
- libgstbasecamerabinsrc-1_0-0-debuginfo-1.8.3-14.1
- libgstbadvideo-1_0-0-1.8.3-14.1
- libgstmpegts-1_0-0-debuginfo-1.8.3-14.1
- libgstbadvideo-1_0-0-debuginfo-1.8.3-14.1
- libgstgl-1_0-0-1.8.3-14.1
- libgstcodecparsers-1_0-0-debuginfo-1.8.3-14.1
- gstreamer-plugins-bad-debugsource-1.8.3-14.1
- libgstbadaudio-1_0-0-1.8.3-14.1
- libgstgl-1_0-0-debuginfo-1.8.3-14.1
- libgstmpegts-1_0-0-1.8.3-14.1
- gstreamer-plugins-bad-1.8.3-14.1
- libgsturidownloader-1_0-0-debuginfo-1.8.3-14.1
- libgstbadbase-1_0-0-1.8.3-14.1
-
SUSE Linux Enterprise Server for the Raspberry Pi 12-SP2 (noarch)
- gstreamer-plugins-bad-lang-1.8.3-14.1
-
SUSE Linux Enterprise Software Development Kit 12 12-SP2 (aarch64 ppc64le s390x x86_64)
- gstreamer-plugins-bad-debuginfo-1.8.3-14.1
- libgsturidownloader-1_0-0-1.8.3-14.1
- libgsturidownloader-1_0-0-debuginfo-1.8.3-14.1
- libgstinsertbin-1_0-0-debuginfo-1.8.3-14.1
- gstreamer-plugins-bad-debugsource-1.8.3-14.1
- gstreamer-plugins-bad-devel-1.8.3-14.1
- libgstinsertbin-1_0-0-1.8.3-14.1
-
SUSE Linux Enterprise High Performance Computing 12 SP2 (aarch64 x86_64)
- gstreamer-plugins-bad-debuginfo-1.8.3-14.1
- libgstphotography-1_0-0-1.8.3-14.1
- libgstphotography-1_0-0-debuginfo-1.8.3-14.1
- libgstbadbase-1_0-0-debuginfo-1.8.3-14.1
- libgstbasecamerabinsrc-1_0-0-1.8.3-14.1
- libgstcodecparsers-1_0-0-1.8.3-14.1
- libgsturidownloader-1_0-0-1.8.3-14.1
- libgstadaptivedemux-1_0-0-1.8.3-14.1
- libgstbadaudio-1_0-0-debuginfo-1.8.3-14.1
- libgstadaptivedemux-1_0-0-debuginfo-1.8.3-14.1
- libgstbasecamerabinsrc-1_0-0-debuginfo-1.8.3-14.1
- libgstbadvideo-1_0-0-1.8.3-14.1
- libgstmpegts-1_0-0-debuginfo-1.8.3-14.1
- libgstbadvideo-1_0-0-debuginfo-1.8.3-14.1
- libgstgl-1_0-0-1.8.3-14.1
- libgstcodecparsers-1_0-0-debuginfo-1.8.3-14.1
- gstreamer-plugins-bad-debugsource-1.8.3-14.1
- libgstbadaudio-1_0-0-1.8.3-14.1
- libgstgl-1_0-0-debuginfo-1.8.3-14.1
- libgstmpegts-1_0-0-1.8.3-14.1
- gstreamer-plugins-bad-1.8.3-14.1
- libgsturidownloader-1_0-0-debuginfo-1.8.3-14.1
- libgstbadbase-1_0-0-1.8.3-14.1
-
SUSE Linux Enterprise High Performance Computing 12 SP2 (noarch)
- gstreamer-plugins-bad-lang-1.8.3-14.1
-
SUSE Linux Enterprise Server 12 SP2 (aarch64 ppc64le s390x x86_64)
- gstreamer-plugins-bad-debuginfo-1.8.3-14.1
- libgstphotography-1_0-0-1.8.3-14.1
- libgstphotography-1_0-0-debuginfo-1.8.3-14.1
- libgstbadbase-1_0-0-debuginfo-1.8.3-14.1
- libgstbasecamerabinsrc-1_0-0-1.8.3-14.1
- libgstcodecparsers-1_0-0-1.8.3-14.1
- libgsturidownloader-1_0-0-1.8.3-14.1
- libgstadaptivedemux-1_0-0-1.8.3-14.1
- libgstbadaudio-1_0-0-debuginfo-1.8.3-14.1
- libgstadaptivedemux-1_0-0-debuginfo-1.8.3-14.1
- libgstbasecamerabinsrc-1_0-0-debuginfo-1.8.3-14.1
- libgstbadvideo-1_0-0-1.8.3-14.1
- libgstmpegts-1_0-0-debuginfo-1.8.3-14.1
- libgstbadvideo-1_0-0-debuginfo-1.8.3-14.1
- libgstgl-1_0-0-1.8.3-14.1
- libgstcodecparsers-1_0-0-debuginfo-1.8.3-14.1
- gstreamer-plugins-bad-debugsource-1.8.3-14.1
- libgstbadaudio-1_0-0-1.8.3-14.1
- libgstgl-1_0-0-debuginfo-1.8.3-14.1
- libgstmpegts-1_0-0-1.8.3-14.1
- gstreamer-plugins-bad-1.8.3-14.1
- libgsturidownloader-1_0-0-debuginfo-1.8.3-14.1
- libgstbadbase-1_0-0-1.8.3-14.1
-
SUSE Linux Enterprise Server 12 SP2 (noarch)
- gstreamer-plugins-bad-lang-1.8.3-14.1
-
SUSE Linux Enterprise Server for SAP Applications 12 SP2 (ppc64le x86_64)
- gstreamer-plugins-bad-debuginfo-1.8.3-14.1
- libgstphotography-1_0-0-1.8.3-14.1
- libgstphotography-1_0-0-debuginfo-1.8.3-14.1
- libgstbadbase-1_0-0-debuginfo-1.8.3-14.1
- libgstbasecamerabinsrc-1_0-0-1.8.3-14.1
- libgstcodecparsers-1_0-0-1.8.3-14.1
- libgsturidownloader-1_0-0-1.8.3-14.1
- libgstadaptivedemux-1_0-0-1.8.3-14.1
- libgstbadaudio-1_0-0-debuginfo-1.8.3-14.1
- libgstadaptivedemux-1_0-0-debuginfo-1.8.3-14.1
- libgstbasecamerabinsrc-1_0-0-debuginfo-1.8.3-14.1
- libgstbadvideo-1_0-0-1.8.3-14.1
- libgstmpegts-1_0-0-debuginfo-1.8.3-14.1
- libgstbadvideo-1_0-0-debuginfo-1.8.3-14.1
- libgstgl-1_0-0-1.8.3-14.1
- libgstcodecparsers-1_0-0-debuginfo-1.8.3-14.1
- gstreamer-plugins-bad-debugsource-1.8.3-14.1
- libgstbadaudio-1_0-0-1.8.3-14.1
- libgstgl-1_0-0-debuginfo-1.8.3-14.1
- libgstmpegts-1_0-0-1.8.3-14.1
- gstreamer-plugins-bad-1.8.3-14.1
- libgsturidownloader-1_0-0-debuginfo-1.8.3-14.1
- libgstbadbase-1_0-0-1.8.3-14.1
-
SUSE Linux Enterprise Server for SAP Applications 12 SP2 (noarch)
- gstreamer-plugins-bad-lang-1.8.3-14.1
References:
- https://www.suse.com/security/cve/CVE-2016-9445.html
- https://www.suse.com/security/cve/CVE-2016-9446.html
- https://www.suse.com/security/cve/CVE-2016-9809.html
- https://www.suse.com/security/cve/CVE-2016-9812.html
- https://www.suse.com/security/cve/CVE-2016-9813.html
- https://bugzilla.suse.com/show_bug.cgi?id=1010829
- https://bugzilla.suse.com/show_bug.cgi?id=1013659
- https://bugzilla.suse.com/show_bug.cgi?id=1013678
- https://bugzilla.suse.com/show_bug.cgi?id=1013680