Debian Security Advisory

DLA-2164-1 gst-plugins-bad0.10 -- LTS security update

Date Reported:
31 Mar 2020
Affected Packages:
gst-plugins-bad0.10
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2015-0797, CVE-2016-9809, CVE-2017-5843, CVE-2017-5848.
More information:

Several issues have been found in gst-plugins-bad0.10, a package containing GStreamer plugins from the bad set.

All issues are about use-after-free, out of bounds reads or buffer overflow in different modules.

For Debian 8 Jessie, these problems have been fixed in version 0.10.23-7.4+deb8u3.

We recommend that you upgrade your gst-plugins-bad0.10 packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS