USN-6269-1: GStreamer Good Plugins vulnerability
2 August 2023
GStreamer Good Plugins could be made to crash or run programs if it opened a specially crafted file.
Releases
Packages
- gst-plugins-good1.0 - GStreamer plugins
Details
It was discovered that GStreamer Good Plugins incorrectly handled certain
FLAC image tags. A remote attacker could use this issue to cause GStreamer
Good Plugins to crash, resulting in a denial of service, or possibly
execute arbitrary code. (CVE-2023-37327)
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 23.04
Ubuntu 22.04
Ubuntu 20.04
In general, a standard system update will make all the necessary changes.
References
Related notices
- USN-6268-1: gstreamer1.0-plugins-base-doc, gstreamer1.0-plugins-base, gstreamer1.0-gl, libgstreamer-gl1.0-0, gst-plugins-base1.0, libgstreamer-plugins-base1.0-0, gstreamer1.0-x, gir1.2-gst-plugins-base-1.0, libgstreamer-plugins-base1.0-dev, gstreamer1.0-plugins-base-apps, gstreamer1.0-alsa