USN-7176-1: GStreamer Good Plugins vulnerabilities
18 December 2024
GStreamer Good Plugins could be made to crash or run programs as your login if it opened a specially crafted file.
Releases
Packages
- gst-plugins-good1.0 - GStreamer plugins
Details
Antonio Morales discovered that GStreamer Good Plugins incorrectly handled
certain malformed media files. An attacker could use these issues to cause
GStreamer Good Plugins to crash, resulting in a denial of service, or
possibly execute arbitrary code.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 24.10
-
gstreamer1.0-gtk3
-
1.24.8-1ubuntu1.1
-
gstreamer1.0-plugins-good
-
1.24.8-1ubuntu1.1
-
gstreamer1.0-pulseaudio
-
1.24.8-1ubuntu1.1
-
gstreamer1.0-qt5
-
1.24.8-1ubuntu1.1
-
gstreamer1.0-qt6
-
1.24.8-1ubuntu1.1
-
libgstreamer-plugins-good1.0-0
-
1.24.8-1ubuntu1.1
Ubuntu 24.04
-
gstreamer1.0-gtk3
-
1.24.2-1ubuntu1.1
-
gstreamer1.0-plugins-good
-
1.24.2-1ubuntu1.1
-
gstreamer1.0-pulseaudio
-
1.24.2-1ubuntu1.1
-
gstreamer1.0-qt5
-
1.24.2-1ubuntu1.1
-
gstreamer1.0-qt6
-
1.24.2-1ubuntu1.1
-
libgstreamer-plugins-good1.0-0
-
1.24.2-1ubuntu1.1
Ubuntu 22.04
-
gstreamer1.0-gtk3
-
1.20.3-0ubuntu1.3
-
gstreamer1.0-plugins-good
-
1.20.3-0ubuntu1.3
-
gstreamer1.0-pulseaudio
-
1.20.3-0ubuntu1.3
-
gstreamer1.0-qt5
-
1.20.3-0ubuntu1.3
-
libgstreamer-plugins-good1.0-0
-
1.20.3-0ubuntu1.3
Ubuntu 20.04
-
gstreamer1.0-gtk3
-
1.16.3-0ubuntu1.3
-
gstreamer1.0-plugins-good
-
1.16.3-0ubuntu1.3
-
gstreamer1.0-pulseaudio
-
1.16.3-0ubuntu1.3
-
gstreamer1.0-qt5
-
1.16.3-0ubuntu1.3
-
libgstreamer-plugins-good1.0-0
-
1.16.3-0ubuntu1.3
In general, a standard system update will make all the necessary changes.
References
- CVE-2024-47537
- CVE-2024-47776
- CVE-2024-47834
- CVE-2024-47545
- CVE-2024-47596
- CVE-2024-47546
- CVE-2024-47603
- CVE-2024-47774
- CVE-2024-47778
- CVE-2024-47540
- CVE-2024-47775
- CVE-2024-47601
- CVE-2024-47543
- CVE-2024-47777
- CVE-2024-47602
- CVE-2024-47544
- CVE-2024-47597
- CVE-2024-47598
- CVE-2024-47599
- CVE-2024-47613
- CVE-2024-47606
- CVE-2024-47539