[ GLSA 202409-13 ] gst-plugins-good: Multiple Vulnerabilities

[email protected] Sun, 22 Sep 2024 07:13:48 -0000
Newsgroups gmane.linux.gentoo.announce
Message-ID <172698922919.7.8676322490221668307@3f85d36892cf>
--===============7115083357200837082==
Content-Type: text/plain; charset="utf-8"

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 202409-13
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                           https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

 Severity: Normal
    Title: gst-plugins-good: Multiple Vulnerabilities
     Date: September 22, 2024
     Bugs: #859418
       ID: 202409-13

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilities have been discovered in gst-plugins-good, the
worst of which could lead to denial of service or arbitrary code
execution.

Background
==========

gst-plugins-good contains a set of plugins for the GStreamer open source
multimedia framework.

Affected packages
=================

Package                      Vulnerable    Unaffected
---------------------------  ------------  ------------
media-libs/gst-plugins-good  < 1.20.3      >= 1.20.3

Description
===========

Multiple vulnerabilities have been discovered in gst-plugins-good.
Please review the CVE identifiers referenced below for details.

Impact
======

Please review the referenced CVE identifiers for details.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All gst-plugins-good users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot --verbose ">=media-libs/gst-plugins-good-1.20.3"

References
==========

[ 1 ] CVE-2022-1920
      https://nvd.nist.gov/vuln/detail/CVE-2022-1920
[ 2 ] CVE-2022-1921
      https://nvd.nist.gov/vuln/detail/CVE-2022-1921
[ 3 ] CVE-2022-1922
      https://nvd.nist.gov/vuln/detail/CVE-2022-1922
[ 4 ] CVE-2022-1923
      https://nvd.nist.gov/vuln/detail/CVE-2022-1923
[ 5 ] CVE-2022-1924
      https://nvd.nist.gov/vuln/detail/CVE-2022-1924
[ 6 ] CVE-2022-1925
      https://nvd.nist.gov/vuln/detail/CVE-2022-1925
[ 7 ] CVE-2022-2122
      https://nvd.nist.gov/vuln/detail/CVE-2022-2122

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

 https://security.gentoo.org/glsa/202409-13

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
[email protected] or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2024 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

https://creativecommons.org/licenses/by-sa/2.5
--===============7115083357200837082==
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmbvw6wACgkQFMQkOaVy
+9lDAA//VaYbnCvQ1bfvubWRyf805Devzv5dHAG6JDCucyjT2w/NxSF4KM0C/aX7
Roy0wIBDOxyvhgsj8dFUw2dwPaFYuGTJgkWQErPzEbrhvKro04d0BwMH7wDvG291
Hlsc460ovvsAKvfN8Izatj2GS6bJMmzug9tqxNAQXzZBloFbk6Nc84lfxAOHkjRK
Oyg8MPAYexvnKzrmztfBMZaszsWSx/Cwy4UCAiV8d129C7wtlahFkuTR5ZYCFOuC
ZsGK28Yh+UKpHrWH9qdRz5SNRkdh5IWjG82r7LSsS3In53PHXc2/m6f91ajhPZwb
mQCMQmFBiVewGkyClEJun1ClfgeYAIA7hADNpfzb4q22W5cyPQIEm5clA6wsfC1g
g1AHrGwMW91rs2qgFWY7etTIh0f8Zhifn6pw8lPyJBNf1BOk4NDktfr/rOIQpjAq
BabIiIiAUwUdP1c4aklCJfB+KYMwm+Bhkw84JynK2hsFRZpbrw+H1JqKezDmBV0h
bzIVQ01ZOqWF/otBvapUgAKxTKnodRThg0FZCj0ul+xfs8wTKxcnY5bEZmFwr4+q
gqiYI8PwZlPIuEjdVF/H5ur1JA2cJOY0GSLJcNtTeD3RzJ8+NDHTtldtxGV07klO
yHElV7bnKfAVyMNyLOhkWWwlb8gPh8YjACmKBdyu2+ee26eqekI=
=xNnJ
-----END PGP SIGNATURE-----

--===============7115083357200837082==--