Red Hat Security Advisory: gstreamer-plugins-good security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2009-0386 — gstreamer-plugins-good: heap-based buffer overflow while parsing malformed QuickTime media files via crafted Composition Time To Sample (aka ctts) atom data CVE-2009-0387 — gstreamer-plugins-good: Array index error while parsing malformed QuickTime media files via crafted Sync Sample (aka stss) atom data CVE-2009-0397 — gstreamer-plugins-good: heap-based buffer overflow while parsing malformed QuickTime media files via crafted Time-to-sample (stss) atom data
🎯 Affected products34
- Red Hat Enterprise Linux (v. 5 server)
- Red Hat Enterprise Linux Desktop (v. 5 client)
- Red Hat Enterprise Linux Desktop Workstation (v. 5 client)
- gstreamer-plugins-good-0:0.10.9-1.el5_3.1.i386 as a component of Red Hat Enterprise Linux (v. 5 server)
- gstreamer-plugins-good-0:0.10.9-1.el5_3.1.i386 as a component of Red Hat Enterprise Linux Desktop (v. 5 client)
- gstreamer-plugins-good-0:0.10.9-1.el5_3.1.ia64 as a component of Red Hat Enterprise Linux (v. 5 server)
- gstreamer-plugins-good-0:0.10.9-1.el5_3.1.ppc as a component of Red Hat Enterprise Linux (v. 5 server)
- gstreamer-plugins-good-0:0.10.9-1.el5_3.1.ppc64 as a component of Red Hat Enterprise Linux (v. 5 server)
- gstreamer-plugins-good-0:0.10.9-1.el5_3.1.s390x as a component of Red Hat Enterprise Linux (v. 5 server)
- gstreamer-plugins-good-0:0.10.9-1.el5_3.1.src as a component of Red Hat Enterprise Linux (v. 5 server)
- gstreamer-plugins-good-0:0.10.9-1.el5_3.1.src as a component of Red Hat Enterprise Linux Desktop (v. 5 client)
- gstreamer-plugins-good-0:0.10.9-1.el5_3.1.src as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)
- gstreamer-plugins-good-0:0.10.9-1.el5_3.1.x86_64 as a component of Red Hat Enterprise Linux (v. 5 server)
- gstreamer-plugins-good-0:0.10.9-1.el5_3.1.x86_64 as a component of Red Hat Enterprise Linux Desktop (v. 5 client)
- gstreamer-plugins-good-debuginfo-0:0.10.9-1.el5_3.1.i386 as a component of Red Hat Enterprise Linux (v. 5 server)
- gstreamer-plugins-good-debuginfo-0:0.10.9-1.el5_3.1.i386 as a component of Red Hat Enterprise Linux Desktop (v. 5 client)
- gstreamer-plugins-good-debuginfo-0:0.10.9-1.el5_3.1.i386 as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)
- gstreamer-plugins-good-debuginfo-0:0.10.9-1.el5_3.1.ia64 as a component of Red Hat Enterprise Linux (v. 5 server)
- gstreamer-plugins-good-debuginfo-0:0.10.9-1.el5_3.1.ppc as a component of Red Hat Enterprise Linux (v. 5 server)
- gstreamer-plugins-good-debuginfo-0:0.10.9-1.el5_3.1.ppc64 as a component of Red Hat Enterprise Linux (v. 5 server)
- gstreamer-plugins-good-debuginfo-0:0.10.9-1.el5_3.1.s390 as a component of Red Hat Enterprise Linux (v. 5 server)
- gstreamer-plugins-good-debuginfo-0:0.10.9-1.el5_3.1.s390x as a component of Red Hat Enterprise Linux (v. 5 server)
- gstreamer-plugins-good-debuginfo-0:0.10.9-1.el5_3.1.x86_64 as a component of Red Hat Enterprise Linux (v. 5 server)
- gstreamer-plugins-good-debuginfo-0:0.10.9-1.el5_3.1.x86_64 as a component of Red Hat Enterprise Linux Desktop (v. 5 client)
- gstreamer-plugins-good-debuginfo-0:0.10.9-1.el5_3.1.x86_64 as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)
- gstreamer-plugins-good-devel-0:0.10.9-1.el5_3.1.i386 as a component of Red Hat Enterprise Linux (v. 5 server)
- gstreamer-plugins-good-devel-0:0.10.9-1.el5_3.1.i386 as a component of Red Hat Enterprise Linux Desktop Workstation (v. 5 client)
- gstreamer-plugins-good-devel-0:0.10.9-1.el5_3.1.ia64 as a component of Red Hat Enterprise Linux (v. 5 server)
- gstreamer-plugins-good-devel-0:0.10.9-1.el5_3.1.ppc as a component of Red Hat Enterprise Linux (v. 5 server)
- gstreamer-plugins-good-devel-0:0.10.9-1.el5_3.1.ppc64 as a component of Red Hat Enterprise Linux (v. 5 server)
- +4 more not shown
✅ Remediation
Before applying this update, make sure that all previously-released errata relevant to your system have been applied. This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at http://kbase.redhat.com/faq/docs/DOC-11259
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2009:0271
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=481267
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=483736
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=483737
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2009/rhsa-2009_0271.json