Synopsis: Moderate: gstreamer-plugins-good security update
Issue date: 2009-06-25
CVE Names: CVE-2009-1932
Multiple integer overflow flaws, that could lead to a buffer overflow,
were found in the GStreamer Good Plug-ins PNG decoding handler. An
attacker could create a specially-crafted PNG file that would cause an
application using the GStreamer Good Plug-ins library to crash or,
potentially, execute arbitrary code as the user running the application
when parsed. (CVE-2009-1932)
After installing the update, all applications using GStreamer Good
Plug-ins (such as some media playing applications) must be restarted for
the changes to take effect.
SL 5.x
SRPMS:
gstreamer-plugins-good-0.10.9-1.el5_3.2.src.rpm
i386:
gstreamer-plugins-good-0.10.9-1.el5_3.2.i386.rpm
gstreamer-plugins-good-devel-0.10.9-1.el5_3.2.i386.rpm
x86_64:
gstreamer-plugins-good-0.10.9-1.el5_3.2.x86_64.rpm
gstreamer-plugins-good-devel-0.10.9-1.el5_3.2.i386.rpm
gstreamer-plugins-good-devel-0.10.9-1.el5_3.2.x86_64.rpm
-Connie Sieh
-Troy Dawson