SUSE-SU-2023:4574-1 -- SLES gstreamer-plugins-bad, libgstphotography-1_0-0, libgstplay-1_0-0, libgstplayer-1_0-0, typelib-1_0-GstBadAudio-1_0, typelib-1_0-GstMpegts-1_0, libgstinsertbin-1_0-0, libgstwebrtc-1_0-0, typelib-1_0-GstPlayer-1_0, typelib-1_0-GstPlay-1_0, libgsttranscoder-1_0-0, libgstwayland-1_0-0, typelib-1_0-GstCodecs-1_0, typelib-1_0-GstInsertBin-1_0, libgstwebrtcnice-1_0-0, libgstadaptivedemux-1_0-0, libgstvulkan-1_0-0, libgstcodecs-1_0-0, libgstsctp-1_0-0, libgstva-1_0-0, libgstcuda-1_0-0, typelib-1_0-CudaGst-1_0, libgsturidownloader-1_0-0, libgstmpegts-1_0-0, typelib-1_0-GstVa-1_0, typelib-1_0-GstCuda-1_0, typelib-1_0-GstWebRTC-1_0, libgstbasecamerabinsrc-1_0-0, libgstbadaudio-1_0-0, libgstcodecparsers-1_0-0, libgstisoff-1_0-0ID: oval:org.secpod.oval:def:89051174 | Date: (C)2024-01-23 (M)2024-01-23 | Class: PATCH | Family: unix |
This update for gstreamer-plugins-bad fixes the following issues: * CVE-2023-40474: Fixed integer overflow causing out of bounds writes when handling invalid uncompressed video . * CVE-2023-40476: Fixed possible overflow using max_sub_layers_minus1 . Platform: | SUSE Linux Enterprise Desktop 15 SP5 | SUSE Linux Enterprise Server 15 SP5 |
Product: | gstreamer-plugins-bad | libgstphotography-1_0-0 | libgstplay-1_0-0 | libgstplayer-1_0-0 | typelib-1_0-GstBadAudio-1_0 | typelib-1_0-GstMpegts-1_0 | libgstinsertbin-1_0-0 | libgstwebrtc-1_0-0 | typelib-1_0-GstPlayer-1_0 | typelib-1_0-GstPlay-1_0 | libgsttranscoder-1_0-0 | libgstwayland-1_0-0 | typelib-1_0-GstCodecs-1_0 | typelib-1_0-GstInsertBin-1_0 | libgstwebrtcnice-1_0-0 | libgstadaptivedemux-1_0-0 | libgstvulkan-1_0-0 | libgstcodecs-1_0-0 | libgstsctp-1_0-0 | libgstva-1_0-0 | libgstcuda-1_0-0 | typelib-1_0-CudaGst-1_0 | libgsturidownloader-1_0-0 | libgstmpegts-1_0-0 | typelib-1_0-GstVa-1_0 | typelib-1_0-GstCuda-1_0 | typelib-1_0-GstWebRTC-1_0 | libgstbasecamerabinsrc-1_0-0 | libgstbadaudio-1_0-0 | libgstcodecparsers-1_0-0 | libgstisoff-1_0-0 |
|