Emilio Pozuelo Monfort pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
381d2632 by Emilio Pozuelo Monfort at 2021-04-23T11:14:02+02:00
CVE-2021-3498/gst-plugins-good1.0 n/a on stretch
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -2058,13 +2058,15 @@ CVE-2021-XXXX [stack corruption when handling files
with more than 64 audio chan
CVE-2021-3498 (GStreamer before 1.18.4 might cause heap corruption when
parsing certa ...)
[experimental] - gst-plugins-good1.0 1.18.4-1
- gst-plugins-good1.0 1.18.4-2 (bug #986911)
+ [stretch] - gst-plugins-good1.0 <not-affected> (Vulnerable code
introduced later)
NOTE: https://gstreamer.freedesktop.org/security/sa-2021-0003.html
- NOTE:
https://gitlab.freedesktop.org/gstreamer/gst-plugins-good/-/commit/02174790726dd20a5c73ce2002189bf240ad4fe0?merge_request_iid=903
+ NOTE:
https://gitlab.freedesktop.org/gstreamer/gst-plugins-good/-/commit/02174790726dd20a5c73ce2002189bf240ad4fe0
+ NOTE: Introduced by:
https://gitlab.freedesktop.org/gstreamer/gst-plugins-good/-/commit/f279bc5336dda19741a5996a108da42dd3201366
CVE-2021-3497 (GStreamer before 1.18.4 might access already-freed memory in
error cod ...)
[experimental] - gst-plugins-good1.0 1.18.4-1
- gst-plugins-good1.0 1.18.4-2 (bug #986910)
NOTE: https://gstreamer.freedesktop.org/security/sa-2021-0002.html
- NOTE:
https://gitlab.freedesktop.org/gstreamer/gst-plugins-good/-/commit/9181191511f9c0be6a89c98b311f49d66bd46dc3?merge_request_iid=903
+ NOTE:
https://gitlab.freedesktop.org/gstreamer/gst-plugins-good/-/commit/9181191511f9c0be6a89c98b311f49d66bd46dc3
CVE-2021-3496 (A heap-based buffer overflow was found in jhead in version 3.06
in Get ...)
- jhead <unfixed> (bug #986923; unimportant)
NOTE: https://github.com/Matthias-Wandel/jhead/issues/33
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/381d2632015d83571dec288799a498797b777973
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/381d2632015d83571dec288799a498797b777973
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits