Summary: | <media-libs/gstreamer-{1.18.6, 1.20.0}: Multiple vulnerabilities | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Sam James <sam> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | minor | CC: | gstreamer |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | B3 [glsa+] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | 835598 | ||
Bug Blocks: |
Description
Sam James
2022-03-15 19:40:28 UTC
So, 1.20.x is fine, but we really want 1.18.6 which we can immediately stable. The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=3bbfabcbf72ad21914c56e510158935e3bafbe89 commit 3bbfabcbf72ad21914c56e510158935e3bafbe89 Author: Igor V. Kovalenko <igor.v.kovalenko@gmail.com> AuthorDate: 2022-03-17 18:53:34 +0000 Commit: Sam James <sam@gentoo.org> CommitDate: 2022-03-18 00:31:41 +0000 media-libs/gstreamer: Version bump, 1.18.6 Bug: https://bugs.gentoo.org/835368 Signed-off-by: Igor V. Kovalenko <igor.v.kovalenko@gmail.com> Closes: https://github.com/gentoo/gentoo/pull/24625 Signed-off-by: Sam James <sam@gentoo.org> dev-python/gst-python/Manifest | 1 + dev-python/gst-python/gst-python-1.18.6.ebuild | 63 +++++++++ media-libs/gst-plugins-bad/Manifest | 1 + .../gst-plugins-bad/gst-plugins-bad-1.18.6.ebuild | 87 ++++++++++++ media-libs/gst-plugins-base/Manifest | 1 + .../gst-plugins-base-1.18.6.ebuild | 150 +++++++++++++++++++++ media-libs/gst-plugins-good/Manifest | 1 + .../gst-plugins-good-1.18.6.ebuild | 49 +++++++ media-libs/gst-plugins-ugly/Manifest | 1 + .../gst-plugins-ugly-1.18.6.ebuild | 31 +++++ media-libs/gst-rtsp-server/Manifest | 1 + .../gst-rtsp-server/gst-rtsp-server-1.18.6.ebuild | 45 +++++++ media-libs/gstreamer/Manifest | 1 + media-libs/gstreamer/gstreamer-1.18.6.ebuild | 70 ++++++++++ media-plugins/gst-plugins-a52dec/Manifest | 1 + .../gst-plugins-a52dec-1.18.6.ebuild | 17 +++ media-plugins/gst-plugins-amr/Manifest | 1 + .../gst-plugins-amr/gst-plugins-amr-1.18.6.ebuild | 20 +++ media-plugins/gst-plugins-aom/Manifest | 1 + .../gst-plugins-aom/gst-plugins-aom-1.18.6.ebuild | 19 +++ media-plugins/gst-plugins-assrender/Manifest | 1 + .../gst-plugins-assrender-1.18.6.ebuild | 14 ++ media-plugins/gst-plugins-bluez/Manifest | 1 + .../gst-plugins-bluez-1.18.6.ebuild | 18 +++ media-plugins/gst-plugins-bs2b/Manifest | 1 + .../gst-plugins-bs2b-1.18.6.ebuild | 16 +++ media-plugins/gst-plugins-cairo/Manifest | 1 + .../gst-plugins-cairo-1.18.6.ebuild | 14 ++ media-plugins/gst-plugins-cdio/Manifest | 1 + .../gst-plugins-cdio-1.18.6.ebuild | 14 ++ media-plugins/gst-plugins-cdparanoia/Manifest | 1 + .../gst-plugins-cdparanoia-1.18.6.ebuild | 19 +++ media-plugins/gst-plugins-chromaprint/Manifest | 1 + .../gst-plugins-chromaprint-1.18.6.ebuild | 13 ++ media-plugins/gst-plugins-colormanagement/Manifest | 1 + .../gst-plugins-colormanagement-1.18.6.ebuild | 13 ++ media-plugins/gst-plugins-dash/Manifest | 1 + .../gst-plugins-dash-1.18.6.ebuild | 23 ++++ media-plugins/gst-plugins-dtls/Manifest | 1 + .../gst-plugins-dtls-1.18.6.ebuild | 16 +++ media-plugins/gst-plugins-dts/Manifest | 1 + .../gst-plugins-dts/gst-plugins-dts-1.18.6.ebuild | 17 +++ media-plugins/gst-plugins-dv/Manifest | 1 + .../gst-plugins-dv/gst-plugins-dv-1.18.6.ebuild | 14 ++ media-plugins/gst-plugins-dvb/Manifest | 1 + .../gst-plugins-dvb/gst-plugins-dvb-1.18.6.ebuild | 19 +++ media-plugins/gst-plugins-dvdread/Manifest | 1 + .../gst-plugins-dvdread-1.18.6.ebuild | 14 ++ media-plugins/gst-plugins-faac/Manifest | 1 + .../gst-plugins-faac-1.18.6.ebuild | 14 ++ media-plugins/gst-plugins-faad/Manifest | 1 + .../gst-plugins-faad-1.18.6.ebuild | 14 ++ media-plugins/gst-plugins-flac/Manifest | 1 + .../gst-plugins-flac-1.18.6.ebuild | 14 ++ media-plugins/gst-plugins-gdkpixbuf/Manifest | 1 + .../gst-plugins-gdkpixbuf-1.18.6.ebuild | 17 +++ media-plugins/gst-plugins-gtk/Manifest | 1 + .../gst-plugins-gtk/gst-plugins-gtk-1.18.6.ebuild | 31 +++++ media-plugins/gst-plugins-hls/Manifest | 1 + .../gst-plugins-hls/gst-plugins-hls-1.18.6.ebuild | 37 +++++ media-plugins/gst-plugins-jack/Manifest | 1 + .../gst-plugins-jack-1.18.6.ebuild | 18 +++ media-plugins/gst-plugins-jpeg/Manifest | 1 + .../gst-plugins-jpeg-1.18.6.ebuild | 14 ++ media-plugins/gst-plugins-kate/Manifest | 1 + .../gst-plugins-kate-1.18.6.ebuild | 17 +++ media-plugins/gst-plugins-ladspa/Manifest | 1 + .../gst-plugins-ladspa-1.18.6.ebuild | 17 +++ media-plugins/gst-plugins-lame/Manifest | 1 + .../gst-plugins-lame-1.18.6.ebuild | 14 ++ media-plugins/gst-plugins-libav/Manifest | 2 + .../gst-plugins-libav-1.18.6-r1.ebuild | 33 +++++ .../gst-plugins-libav-1.18.6.ebuild | 28 ++++ media-plugins/gst-plugins-libde265/Manifest | 1 + .../gst-plugins-libde265-1.18.6.ebuild | 16 +++ media-plugins/gst-plugins-libmms/Manifest | 1 + .../gst-plugins-libmms-1.18.6.ebuild | 14 ++ media-plugins/gst-plugins-libpng/Manifest | 1 + .../gst-plugins-libpng-1.18.6.ebuild | 16 +++ media-plugins/gst-plugins-libvisual/Manifest | 1 + .../gst-plugins-libvisual-1.18.6.ebuild | 24 ++++ media-plugins/gst-plugins-lv2/Manifest | 1 + .../gst-plugins-lv2/gst-plugins-lv2-1.18.6.ebuild | 17 +++ .../gst-plugins-meta-1.18.6.ebuild | 69 ++++++++++ media-plugins/gst-plugins-modplug/Manifest | 1 + .../gst-plugins-modplug-1.18.6.ebuild | 14 ++ media-plugins/gst-plugins-mpeg2dec/Manifest | 1 + .../gst-plugins-mpeg2dec-1.18.6.ebuild | 14 ++ media-plugins/gst-plugins-mpeg2enc/Manifest | 1 + .../gst-plugins-mpeg2enc-1.18.6.ebuild | 14 ++ media-plugins/gst-plugins-mpg123/Manifest | 1 + .../gst-plugins-mpg123-1.18.6.ebuild | 16 +++ media-plugins/gst-plugins-mplex/Manifest | 1 + .../gst-plugins-mplex-1.18.6.ebuild | 14 ++ media-plugins/gst-plugins-neon/Manifest | 1 + .../gst-plugins-neon-1.18.6.ebuild | 16 +++ media-plugins/gst-plugins-ofa/Manifest | 1 + .../gst-plugins-ofa/gst-plugins-ofa-1.18.6.ebuild | 14 ++ media-plugins/gst-plugins-opencv/Manifest | 1 + ...plugins-bad-1.18.6-use-system-libs-opencv.patch | 81 +++++++++++ .../gst-plugins-opencv-1.18.6.ebuild | 32 +++++ media-plugins/gst-plugins-openh264/Manifest | 1 + .../gst-plugins-openh264-1.18.6.ebuild | 16 +++ media-plugins/gst-plugins-opus/Manifest | 2 + .../gst-plugins-opus-1.18.6.ebuild | 55 ++++++++ media-plugins/gst-plugins-oss/Manifest | 1 + .../gst-plugins-oss/gst-plugins-oss-1.18.6.ebuild | 14 ++ media-plugins/gst-plugins-pulse/Manifest | 1 + .../gst-plugins-pulse-1.18.6.ebuild | 17 +++ media-plugins/gst-plugins-raw1394/Manifest | 1 + .../gst-plugins-raw1394-1.18.6.ebuild | 21 +++ media-plugins/gst-plugins-resindvd/Manifest | 1 + .../gst-plugins-resindvd-1.18.6.ebuild | 17 +++ media-plugins/gst-plugins-rtmp/Manifest | 1 + .../gst-plugins-rtmp-1.18.6.ebuild | 14 ++ media-plugins/gst-plugins-sctp/Manifest | 1 + .../gst-plugins-sctp-1.18.6.ebuild | 16 +++ media-plugins/gst-plugins-shout2/Manifest | 1 + .../gst-plugins-shout2-1.18.6.ebuild | 14 ++ media-plugins/gst-plugins-sidplay/Manifest | 1 + .../gst-plugins-sidplay-1.18.6.ebuild | 14 ++ media-plugins/gst-plugins-smoothstreaming/Manifest | 1 + .../gst-plugins-smoothstreaming-1.18.6.ebuild | 22 +++ media-plugins/gst-plugins-soundtouch/Manifest | 1 + .../gst-plugins-soundtouch-1.18.6.ebuild | 14 ++ media-plugins/gst-plugins-soup/Manifest | 1 + .../gst-plugins-soup-1.18.6.ebuild | 14 ++ media-plugins/gst-plugins-speex/Manifest | 1 + .../gst-plugins-speex-1.18.6.ebuild | 14 ++ media-plugins/gst-plugins-srt/Manifest | 1 + .../gst-plugins-srt/gst-plugins-srt-1.18.6.ebuild | 16 +++ media-plugins/gst-plugins-srtp/Manifest | 1 + .../gst-plugins-srtp-1.18.6.ebuild | 17 +++ media-plugins/gst-plugins-taglib/Manifest | 1 + .../gst-plugins-taglib-1.18.6.ebuild | 14 ++ media-plugins/gst-plugins-twolame/Manifest | 1 + .../gst-plugins-twolame-1.18.6.ebuild | 14 ++ media-plugins/gst-plugins-uvch264/Manifest | 1 + .../gst-plugins-uvch264-1.18.6.ebuild | 22 +++ media-plugins/gst-plugins-v4l2/Manifest | 1 + .../gst-plugins-v4l2-1.18.6.ebuild | 30 +++++ media-plugins/gst-plugins-vaapi/Manifest | 1 + .../gst-plugins-vaapi-1.18.6.ebuild | 101 ++++++++++++++ media-plugins/gst-plugins-voaacenc/Manifest | 1 + .../gst-plugins-voaacenc-1.18.6.ebuild | 14 ++ media-plugins/gst-plugins-voamrwbenc/Manifest | 1 + .../gst-plugins-voamrwbenc-1.18.6.ebuild | 14 ++ media-plugins/gst-plugins-vpx/Manifest | 1 + .../gst-plugins-vpx/gst-plugins-vpx-1.18.6.ebuild | 14 ++ media-plugins/gst-plugins-wavpack/Manifest | 1 + .../gst-plugins-wavpack-1.18.6.ebuild | 14 ++ media-plugins/gst-plugins-webrtc/Manifest | 1 + .../gst-plugins-webrtc-1.18.6.ebuild | 43 ++++++ media-plugins/gst-plugins-x264/Manifest | 1 + .../gst-plugins-x264-1.18.6.ebuild | 15 +++ media-plugins/gst-plugins-x265/Manifest | 1 + .../gst-plugins-x265-1.18.6.ebuild | 16 +++ media-plugins/gst-plugins-ximagesrc/Manifest | 1 + .../gst-plugins-ximagesrc-1.18.6.ebuild | 35 +++++ media-plugins/gst-plugins-zbar/Manifest | 1 + .../gst-plugins-zbar-1.18.6.ebuild | 14 ++ 161 files changed, 2150 insertions(+) 1.20.x shadows this in ~arch, so it won't receive much natural testing by users, so we'll stabilise soon. The changes are pretty minor overall (nothing scary looking). GLSA request filed The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/data/glsa.git/commit/?id=f69203b9608d0db5bda6ce4050bf90de5119c0f8 commit f69203b9608d0db5bda6ce4050bf90de5119c0f8 Author: GLSAMaker <glsamaker@gentoo.org> AuthorDate: 2022-08-14 21:47:49 +0000 Commit: Sam James <sam@gentoo.org> CommitDate: 2022-08-14 21:48:21 +0000 [ GLSA 202208-31 ] GStreamer, GStreamer Plugins: Multiple Vulnerabilities Bug: https://bugs.gentoo.org/765163 Bug: https://bugs.gentoo.org/766336 Bug: https://bugs.gentoo.org/785652 Bug: https://bugs.gentoo.org/785655 Bug: https://bugs.gentoo.org/785658 Bug: https://bugs.gentoo.org/785661 Bug: https://bugs.gentoo.org/835368 Bug: https://bugs.gentoo.org/843770 Signed-off-by: GLSAMaker <glsamaker@gentoo.org> Signed-off-by: Sam James <sam@gentoo.org> glsa-202208-31.xml | 111 +++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 111 insertions(+) GLSA done, all done. |