-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3821-1 security@xxxxxxxxxx https://www.debian.org/security/ Moritz Muehlenhoff March 27, 2017 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : gst-plugins-ugly1.0 CVE ID : CVE-2017-5846 CVE-2017-5847 Hanno Boeck discovered multiple vulnerabilities in the GStreamer media framework and its codecs and demuxers, which may result in denial of service or the execution of arbitrary code if a malformed media file is opened. For the stable distribution (jessie), these problems have been fixed in version 1.4.4-2+deb8u1. For the upcoming stable distribution (stretch), these problems have been fixed in version 1.10.4-1. For the unstable distribution (sid), these problems have been fixed in version 1.10.4-1. We recommend that you upgrade your gst-plugins-ugly1.0 packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@xxxxxxxxxxxxxxxx -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAljZeVEACgkQEMKTtsN8 TjaxYA//Qnfi2kL45WWACv2b+ABA6MqthGimYls9KNk8KC++maOTvjA3XgEsRiTQ vY+Y5frNZWTtJqXAeSFebczRVZqsznzRXEYrtepR9/R3zxwgax3nbTzdXPVqqKRx WIO+ZLWjuz7EkH4U1Y0E2q7LeNvA6kMKXCyACrqGnNFUh/cwtCBMmsQFTXUzvD3T ztGeUkvgxFPehjn9udWOYlMCrsjNM3XVFqVfRePph7f5yIiuwfST5GyhGdpQGJSJ mSNG5aZklDuqwSigGc8V3O45CXoN0VzAwh2YNgaIvGSUNsCFRokPfqiHwlr43K4A DRlQbLvIoWQk4QYzymDVkMJxIqv1IOY8LtqFc+CAu+aIVNet3UsBdlzvILulOzdU sCsz1UMQ1QsSfro5LFbgZ3854pzRlStu9ZgI2U5ORK1l/Da5hdgF9ZzDtgY0sOGj 2J2TwsGMnUan3/zIORTi3bcfDHhHh2gPXavCb7JHrOT5zUh9WbDTGDY3OBM2G46E HB4eGYsK5I98rVIBI3a46lR2LP36GCn+DLpugb+Djr11K6FR0p5JkhK+OIco47j1 YBDb/RxoBj6kIBuLL7WBgkoDA4HCruCrdjmtDBIfrgnVnIcdkaV8luX0wU/dAHfV bUzQ817GxCh69tuXn85Qsr8kIuynzsg0bgovRMqBry1VKsVq6d8= =y39H -----END PGP SIGNATURE-----