Oval Definition:oval:com.redhat.rhsa:def:20172060
Revision Date:2017-08-01Version:644
Title:RHSA-2017:2060: GStreamer security, bug fix, and enhancement update (Moderate)
Description:GStreamer is a streaming media framework based on graphs of filters which operate on media data.

The following packages have been upgraded to a later upstream version: clutter-gst2 (2.0.18), gnome-video-effects (0.4.3), gstreamer1 (1.10.4), gstreamer1-plugins-bad-free (1.10.4), gstreamer1-plugins-base (1.10.4), gstreamer1-plugins-good (1.10.4), orc (0.4.26).

Security Fix(es):

  • Multiple flaws were found in gstreamer1, gstreamer1-plugins-base, gstreamer1-plugins-good, and gstreamer1-plugins-bad-free packages. An attacker could potentially use these flaws to crash applications which use the GStreamer framework. (CVE-2016-9446, CVE-2016-9810, CVE-2016-9811, CVE-2016-10198, CVE-2016-10199, CVE-2017-5837, CVE-2017-5838, CVE-2017-5839, CVE-2017-5840, CVE-2017-5841, CVE-2017-5842, CVE-2017-5843, CVE-2017-5844, CVE-2017-5845, CVE-2017-5848)

    Additional Changes:

    For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.4 Release Notes linked from the References section.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2016-10198
    CVE-2016-10199
    CVE-2016-9446
    CVE-2016-9810
    CVE-2016-9811
    CVE-2017-5837
    CVE-2017-5838
    CVE-2017-5839
    CVE-2017-5840
    CVE-2017-5841
    CVE-2017-5842
    CVE-2017-5843
    CVE-2017-5844
    CVE-2017-5845
    CVE-2017-5848
    RHSA-2017:2060
    RHSA-2017:2060-01
    Platform(s):Red Hat Enterprise Linux 7
    Red Hat Enterprise Linux 7 (please do not use for >= RHEL-7.5)
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND
  • orc is earlier than 0:0.4.26-1.el7
  • AND orc is signed with Red Hat redhatrelease2 key
  • orc-compiler is earlier than 0:0.4.26-1.el7
  • AND orc-compiler is signed with Red Hat redhatrelease2 key
  • orc-devel is earlier than 0:0.4.26-1.el7
  • AND orc-devel is signed with Red Hat redhatrelease2 key
  • orc-doc is earlier than 0:0.4.26-1.el7
  • AND orc-doc is signed with Red Hat redhatrelease2 key
  • gstreamer-plugins-good is earlier than 0:0.10.31-13.el7
  • AND gstreamer-plugins-good is signed with Red Hat redhatrelease2 key
  • gstreamer-plugins-good-devel-docs is earlier than 0:0.10.31-13.el7
  • AND gstreamer-plugins-good-devel-docs is signed with Red Hat redhatrelease2 key
  • gstreamer-plugins-bad-free is earlier than 0:0.10.23-23.el7
  • AND gstreamer-plugins-bad-free is signed with Red Hat redhatrelease2 key
  • gstreamer-plugins-bad-free-devel is earlier than 0:0.10.23-23.el7
  • AND gstreamer-plugins-bad-free-devel is signed with Red Hat redhatrelease2 key
  • gstreamer-plugins-bad-free-devel-docs is earlier than 0:0.10.23-23.el7
  • AND gstreamer-plugins-bad-free-devel-docs is signed with Red Hat redhatrelease2 key
  • clutter-gst2 is earlier than 0:2.0.18-1.el7
  • AND clutter-gst2 is signed with Red Hat redhatrelease2 key
  • clutter-gst2-devel is earlier than 0:2.0.18-1.el7
  • AND clutter-gst2-devel is signed with Red Hat redhatrelease2 key
  • gnome-video-effects is earlier than 0:0.4.3-1.el7
  • AND gnome-video-effects is signed with Red Hat redhatrelease2 key
  • gstreamer1-plugins-base is earlier than 0:1.10.4-1.el7
  • AND gstreamer1-plugins-base is signed with Red Hat redhatrelease2 key
  • gstreamer1-plugins-base-devel is earlier than 0:1.10.4-1.el7
  • AND gstreamer1-plugins-base-devel is signed with Red Hat redhatrelease2 key
  • gstreamer1-plugins-base-devel-docs is earlier than 0:1.10.4-1.el7
  • AND gstreamer1-plugins-base-devel-docs is signed with Red Hat redhatrelease2 key
  • gstreamer1-plugins-base-tools is earlier than 0:1.10.4-1.el7
  • AND gstreamer1-plugins-base-tools is signed with Red Hat redhatrelease2 key
  • gstreamer1 is earlier than 0:1.10.4-2.el7
  • AND gstreamer1 is signed with Red Hat redhatrelease2 key
  • gstreamer1-devel is earlier than 0:1.10.4-2.el7
  • AND gstreamer1-devel is signed with Red Hat redhatrelease2 key
  • gstreamer1-devel-docs is earlier than 0:1.10.4-2.el7
  • AND gstreamer1-devel-docs is signed with Red Hat redhatrelease2 key
  • gstreamer1-plugins-good is earlier than 0:1.10.4-2.el7
  • AND gstreamer1-plugins-good is signed with Red Hat redhatrelease2 key
  • gstreamer1-plugins-bad-free is earlier than 0:1.10.4-2.el7
  • AND gstreamer1-plugins-bad-free is signed with Red Hat redhatrelease2 key
  • gstreamer1-plugins-bad-free-devel is earlier than 0:1.10.4-2.el7
  • AND gstreamer1-plugins-bad-free-devel is signed with Red Hat redhatrelease2 key
  • gstreamer1-plugins-bad-free-gtk is earlier than 0:1.10.4-2.el7
  • AND gstreamer1-plugins-bad-free-gtk is signed with Red Hat redhatrelease2 key
  • Definition Synopsis
  • Release Information
  • Red Hat Enterprise Linux 7 Client is installed
  • OR Red Hat Enterprise Linux 7 Server is installed
  • OR Red Hat Enterprise Linux 7 Workstation is installed
  • OR Red Hat Enterprise Linux 7 ComputeNode is installed
  • AND Package Information
  • orc-doc is earlier than 0:0.4.26-1.el7
  • AND orc-doc is signed with Red Hat redhatrelease2 key
  • OR
  • orc-compiler is earlier than 0:0.4.26-1.el7
  • AND orc-compiler is signed with Red Hat redhatrelease2 key
  • OR
  • orc-devel is earlier than 0:0.4.26-1.el7
  • AND orc-devel is signed with Red Hat redhatrelease2 key
  • OR
  • orc is earlier than 0:0.4.26-1.el7
  • AND orc is signed with Red Hat redhatrelease2 key
  • OR
  • gstreamer-plugins-good-devel-docs is earlier than 0:0.10.31-13.el7
  • AND gstreamer-plugins-good-devel-docs is signed with Red Hat redhatrelease2 key
  • OR
  • gstreamer-plugins-good is earlier than 0:0.10.31-13.el7
  • AND gstreamer-plugins-good is signed with Red Hat redhatrelease2 key
  • OR
  • gstreamer-plugins-bad-free-devel is earlier than 0:0.10.23-23.el7
  • AND gstreamer-plugins-bad-free-devel is signed with Red Hat redhatrelease2 key
  • OR
  • gstreamer-plugins-bad-free-devel-docs is earlier than 0:0.10.23-23.el7
  • AND gstreamer-plugins-bad-free-devel-docs is signed with Red Hat redhatrelease2 key
  • OR
  • gstreamer-plugins-bad-free is earlier than 0:0.10.23-23.el7
  • AND gstreamer-plugins-bad-free is signed with Red Hat redhatrelease2 key
  • OR
  • clutter-gst2-devel is earlier than 0:2.0.18-1.el7
  • AND clutter-gst2-devel is signed with Red Hat redhatrelease2 key
  • OR
  • clutter-gst2 is earlier than 0:2.0.18-1.el7
  • AND clutter-gst2 is signed with Red Hat redhatrelease2 key
  • OR
  • gnome-video-effects is earlier than 0:0.4.3-1.el7
  • AND gnome-video-effects is signed with Red Hat redhatrelease2 key
  • OR
  • gstreamer1-plugins-base-devel-docs is earlier than 0:1.10.4-1.el7
  • AND gstreamer1-plugins-base-devel-docs is signed with Red Hat redhatrelease2 key
  • OR
  • gstreamer1-plugins-base-devel is earlier than 0:1.10.4-1.el7
  • AND gstreamer1-plugins-base-devel is signed with Red Hat redhatrelease2 key
  • OR
  • gstreamer1-plugins-base-tools is earlier than 0:1.10.4-1.el7
  • AND gstreamer1-plugins-base-tools is signed with Red Hat redhatrelease2 key
  • OR
  • gstreamer1-plugins-base is earlier than 0:1.10.4-1.el7
  • AND gstreamer1-plugins-base is signed with Red Hat redhatrelease2 key
  • OR
  • gstreamer1-devel is earlier than 0:1.10.4-2.el7
  • AND gstreamer1-devel is signed with Red Hat redhatrelease2 key
  • OR
  • gstreamer1-devel-docs is earlier than 0:1.10.4-2.el7
  • AND gstreamer1-devel-docs is signed with Red Hat redhatrelease2 key
  • OR
  • gstreamer1 is earlier than 0:1.10.4-2.el7
  • AND gstreamer1 is signed with Red Hat redhatrelease2 key
  • OR
  • gstreamer1-plugins-good is earlier than 0:1.10.4-2.el7
  • AND gstreamer1-plugins-good is signed with Red Hat redhatrelease2 key
  • OR
  • gstreamer1-plugins-bad-free-devel is earlier than 0:1.10.4-2.el7
  • AND gstreamer1-plugins-bad-free-devel is signed with Red Hat redhatrelease2 key
  • OR
  • gstreamer1-plugins-bad-free-gtk is earlier than 0:1.10.4-2.el7
  • AND gstreamer1-plugins-bad-free-gtk is signed with Red Hat redhatrelease2 key
  • OR
  • gstreamer1-plugins-bad-free is earlier than 0:1.10.4-2.el7
  • AND gstreamer1-plugins-bad-free is signed with Red Hat redhatrelease2 key
  • BACK