Oval Definition:oval:com.redhat.rhsa:def:20090271
Revision Date:2009-02-06Version:641
Title:RHSA-2009:0271: gstreamer-plugins-good security update (Important)
Description:GStreamer is a streaming media framework, based on graphs of filters which operate on media data. GStreamer Good Plug-ins is a collection of well-supported, GStreamer plug-ins of good quality released under the LGPL license.

  • Multiple heap buffer overflows and an array indexing error were found in the GStreamer's QuickTime media file format decoding plugin. An attacker could create a carefully-crafted QuickTime media .mov file that would cause an application using GStreamer to crash or, potentially, execute arbitrary code if played by a victim. (CVE-2009-0386, CVE-2009-0387, CVE-2009-0397)

    All users of gstreamer-plugins-good are advised to upgrade to these updated packages, which contain backported patches to correct these issues. After installing the update, all applications using GStreamer (such as totem or rhythmbox) must be restarted for the changes to take effect.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2009-0386
    CVE-2009-0387
    CVE-2009-0397
    RHSA-2009:0271
    RHSA-2009:0271-02
    RHSA-2009:0271-02
    Platform(s):Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • gstreamer-plugins-good is earlier than 0:0.10.9-1.el5_3.1
  • AND gstreamer-plugins-good is signed with Red Hat redhatrelease2 key
  • gstreamer-plugins-good-devel is earlier than 0:0.10.9-1.el5_3.1
  • AND gstreamer-plugins-good-devel is signed with Red Hat redhatrelease2 key
  • BACK