Lucene search

K
redhatRedHatRHSA-2009:0352
HistoryApr 06, 2009 - 12:00 a.m.

(RHSA-2009:0352) Moderate: gstreamer-plugins-base security update

2009-04-0600:00:00
access.redhat.com
21

EPSS

0.011

Percentile

84.6%

GStreamer is a streaming media framework based on graphs of filters which
operate on media data. GStreamer Base Plug-ins is a collection of
well-maintained base plug-ins.

An integer overflow flaw which caused a heap-based buffer overflow was
discovered in the Vorbis comment tags reader. An attacker could create a
carefully-crafted Vorbis file that would cause an application using
GStreamer to crash or, potentially, execute arbitrary code if opened by a
victim. (CVE-2009-0586)

All users of gstreamer-plugins-base are advised to upgrade to these updated
packages, which contain a backported patch to correct this issue. After
installing this update, all applications using GStreamer (such as Totem or
Rhythmbox) must be restarted for the changes to take effect.