Gentoo Archives: gentoo-announce

From: glsamaker@g.o
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 202208-31 ] GStreamer, GStreamer Plugins: Multiple Vulnerabilities
Date: Sun, 14 Aug 2022 21:53:43
Message-Id: 166051367393.12.3139408283666350092@7b72ab9f548d
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 202208-31
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: High
8 Title: GStreamer, GStreamer Plugins: Multiple Vulnerabilities
9 Date: August 14, 2022
10 Bugs: #766336, #785652, #785655, #785658, #785661, #835368, #843770, #765163
11 ID: 202208-31
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been found in GStreamer and its plugins,
19 the worst of which could result in arbitrary code execution.
20
21 Background
22 ==========
23
24 GStreamer is an open source multimedia framework.
25
26 Affected packages
27 =================
28
29 -------------------------------------------------------------------
30 Package / Vulnerable / Unaffected
31 -------------------------------------------------------------------
32 1 media-libs/gst-plugins-bad < 1.16.3 >= 1.16.3
33 2 media-libs/gst-plugins-base< 1.18.4 >= 1.18.4
34 3 media-libs/gst-plugins-good< 1.18.4 >= 1.18.4
35 4 media-libs/gst-plugins-ugly< 1.18.4 >= 1.18.4
36 5 media-libs/gstreamer < 1.20.2 >= 1.20.2
37 6 media-plugins/gst-plugins-libav< 1.18.4 >= 1.18.4
38
39 Description
40 ===========
41
42 Multiple vulnerabilities have been found in GStreamer and its plugins.
43 Please review the CVE and GStreamer-SA identifiers referenced below for
44 details.
45
46 Impact
47 ======
48
49 Please review the referenced CVE identifiers for details.
50
51 Workaround
52 ==========
53
54 There is no known workaround at this time.
55
56 Resolution
57 ==========
58
59 All GStreamer users should update to the latest version:
60
61 # emerge --sync
62 # emerge --ask --oneshot --verbose ">=media-libs/gstreamer-1.20.2"
63
64 All gst-plugins-bad users should update to the latest version:
65
66 # emerge --sync
67 # emerge --ask --oneshot --verbose ">=media-libs/gst-plugins-bad-1.20.2"
68
69 All gst-plugins-good users should update to the latest version:
70
71 # emerge --sync
72 # emerge --ask --oneshot --verbose ">=media-libs/gst-plugins-good-1.20.2"
73
74 All gst-plugins-ugly users should update to the latest version:
75
76 # emerge --sync
77 # emerge --ask --oneshot --verbose ">=media-libs/gst-plugins-ugly-1.20.2"
78
79 All gst-plugins-base users should update to the latest version:
80
81 # emerge --sync
82 # emerge --ask --oneshot --verbose ">=media-libs/gst-plugins-base-1.20.2"
83
84 All gst-plugins-libav users should update to the latest version:
85
86 # emerge --sync
87 # emerge --ask --oneshot --verbose ">=media-plugins/gst-plugins-libav-1.20.2"
88
89 References
90 ==========
91
92 [ 1 ] CVE-2021-3185
93 https://nvd.nist.gov/vuln/detail/CVE-2021-3185
94 [ 2 ] CVE-2021-3497
95 https://nvd.nist.gov/vuln/detail/CVE-2021-3497
96 [ 3 ] CVE-2021-3498
97 https://nvd.nist.gov/vuln/detail/CVE-2021-3498
98 [ 4 ] CVE-2021-3522
99 https://nvd.nist.gov/vuln/detail/CVE-2021-3522
100 [ 5 ] GStreamer-SA-2021-0001
101 [ 6 ] GStreamer-SA-2021-0002
102 [ 7 ] GStreamer-SA-2021-0004
103 [ 8 ] GStreamer-SA-2021-0005
104
105 Availability
106 ============
107
108 This GLSA and any updates to it are available for viewing at
109 the Gentoo Security Website:
110
111 https://security.gentoo.org/glsa/202208-31
112
113 Concerns?
114 =========
115
116 Security is a primary focus of Gentoo Linux and ensuring the
117 confidentiality and security of our users' machines is of utmost
118 importance to us. Any security concerns should be addressed to
119 security@g.o or alternatively, you may file a bug at
120 https://bugs.gentoo.org.
121
122 License
123 =======
124
125 Copyright 2022 Gentoo Foundation, Inc; referenced text
126 belongs to its owner(s).
127
128 The contents of this document are licensed under the
129 Creative Commons - Attribution / Share Alike license.
130
131 https://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature