-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-919bc7e512 2024-07-01 01:33:14.869075 -------------------------------------------------------------------------------- Name : mingw-gstreamer1-plugins-base Product : Fedora 39 Version : 1.22.9 Release : 2.fc39 URL : http://gstreamer.freedesktop.org/ Summary : Cross compiled GStreamer1 media framework base plug-ins Description : GStreamer is a streaming media framework, based on graphs of filters which operate on media data. Applications using this library can do anything from real-time sound processing to playing videos, and just about anything else media-related. Its plugin-based architecture means that new data types or processing capabilities can be added simply by installing new plug-ins. This package contains a set of well-maintained base plug-ins. -------------------------------------------------------------------------------- Update Information: Update to gstreamer-1.22.9. Backport fix for CVE-2024-0444. -------------------------------------------------------------------------------- ChangeLog: * Sat Jun 22 2024 Sandro Mani <manisandro@xxxxxxxxx> - 1.22.9-2 - Backport fix for CVE-2024-4453 * Sat Jan 27 2024 Sandro Mani <manisandro@xxxxxxxxx> - 1.22.9-1 - Update to 1.22.9 * Thu Jan 25 2024 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 1.22.8-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Sun Jan 21 2024 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 1.22.8-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Wed Dec 20 2023 Sandro Mani <manisandro@xxxxxxxxx> - 1.22.8-1 - Update to 1.22.8 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2283001 - CVE-2024-4453 mingw-gstreamer1: gstreamer: EXIF Metadata Parsing Integer Overflow [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2283001 [ 2 ] Bug #2292337 - CVE-2024-0444 mingw-gstreamer1: gstreamer: AV1 Video Parsing Stack-based Buffer Overflow [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2292337 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-919bc7e512' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- package-announce@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to package-announce-leave@xxxxxxxxxxxxxxxxxxxxxxx Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/package-announce@xxxxxxxxxxxxxxxxxxxxxxx Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue