Oval Definition:oval:com.redhat.rhsa:def:20090352
Revision Date:2009-04-06Version:636
Title:RHSA-2009:0352: gstreamer-plugins-base security update (Moderate)
Description:GStreamer is a streaming media framework based on graphs of filters which operate on media data. GStreamer Base Plug-ins is a collection of well-maintained base plug-ins.

  • An integer overflow flaw which caused a heap-based buffer overflow was discovered in the Vorbis comment tags reader. An attacker could create a carefully-crafted Vorbis file that would cause an application using GStreamer to crash or, potentially, execute arbitrary code if opened by a victim. (CVE-2009-0586)

    All users of gstreamer-plugins-base are advised to upgrade to these updated packages, which contain a backported patch to correct this issue. After installing this update, all applications using GStreamer (such as Totem or Rhythmbox) must be restarted for the changes to take effect.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2009-0586
    RHSA-2009:0352
    RHSA-2009:0352-01
    RHSA-2009:0352-01
    Platform(s):Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • gstreamer-plugins-base is earlier than 0:0.10.20-3.0.1.el5_3
  • AND gstreamer-plugins-base is signed with Red Hat redhatrelease2 key
  • gstreamer-plugins-base-devel is earlier than 0:0.10.20-3.0.1.el5_3
  • AND gstreamer-plugins-base-devel is signed with Red Hat redhatrelease2 key
  • BACK