Skip to navigation

Security Advisory Important: gstreamer-plugins security update

Advisory: RHSA-2011:0477-1
Type: Security Advisory
Severity: Important
Issued on: 2011-05-02
Last updated on: 2011-05-02
Affected Products: Red Hat Desktop (v. 4)
Red Hat Enterprise Linux AS (v. 4)
Red Hat Enterprise Linux AS (v. 4.8.z)
Red Hat Enterprise Linux ES (v. 4)
Red Hat Enterprise Linux ES (v. 4.8.z)
Red Hat Enterprise Linux WS (v. 4)
CVEs (cve.mitre.org): CVE-2006-4192
CVE-2011-1574

Details

Updated gstreamer-plugins packages that fix two security issues are now
available for Red Hat Enterprise Linux 4.

The Red Hat Security Response Team has rated this update as having
important security impact. Common Vulnerability Scoring System (CVSS) base
scores, which give detailed severity ratings, are available for each
vulnerability from the CVE links in the References section.

The gstreamer-plugins packages contain plug-ins used by the GStreamer
streaming-media framework to support a wide variety of media formats.

An integer overflow flaw, leading to a heap-based buffer overflow, and a
stack-based buffer overflow flaw were found in various ModPlug music file
format library (libmodplug) modules, embedded in GStreamer. An attacker
could create specially-crafted music files that, when played by a victim,
would cause applications using GStreamer to crash or, potentially, execute
arbitrary code. (CVE-2006-4192, CVE-2011-1574)

All users of gstreamer-plugins are advised to upgrade to these updated
packages, which contain backported patches to correct these issues. After
installing the update, all applications using GStreamer (such as Rhythmbox)
must be restarted for the changes to take effect.


Solution

Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/kb/docs/DOC-11259

Updated packages

Red Hat Desktop (v. 4)

SRPMS:
gstreamer-plugins-0.8.5-1.EL.3.src.rpm
File outdated by:  RHSA-2011:1264
    MD5: 688ea081bc8a9281c5a1132a85218ed9
SHA-256: 6224b7d9a1572a98d9322948aaf7402e51dbf6e689a310bad898c7a4802092fb
 
IA-32:
gstreamer-plugins-0.8.5-1.EL.3.i386.rpm
File outdated by:  RHSA-2011:1264
    MD5: 99fa2ba7086d8b3f4140f089f88f59f4
SHA-256: e6a0ce4134c6a3d28dd5d24a4110eb98e8915220cab6c82af40f6eadce629722
gstreamer-plugins-devel-0.8.5-1.EL.3.i386.rpm
File outdated by:  RHSA-2011:1264
    MD5: 3272af4ed8afc230bb399896abee56cd
SHA-256: a2040aa0835f9040059d47573cf00514835c468c418f8c14a01fbfb77494d9ec
 
x86_64:
gstreamer-plugins-0.8.5-1.EL.3.x86_64.rpm
File outdated by:  RHSA-2011:1264
    MD5: 2c5868a9c7fae56c57b6e6c77e19a51b
SHA-256: 88d62b96f925016d1a062b9f2c6a9b705ea01e005194d55134d527d5cc29095e
gstreamer-plugins-devel-0.8.5-1.EL.3.x86_64.rpm
File outdated by:  RHSA-2011:1264
    MD5: 6f185249017b780ade27020ef7b946fe
SHA-256: 210073fa2fdbc6fcd975e590bd954285aff38a2541810fae90360dc7deb724e6
 
Red Hat Enterprise Linux AS (v. 4)

SRPMS:
gstreamer-plugins-0.8.5-1.EL.3.src.rpm
File outdated by:  RHSA-2011:1264
    MD5: 688ea081bc8a9281c5a1132a85218ed9
SHA-256: 6224b7d9a1572a98d9322948aaf7402e51dbf6e689a310bad898c7a4802092fb
 
IA-32:
gstreamer-plugins-0.8.5-1.EL.3.i386.rpm
File outdated by:  RHSA-2011:1264
    MD5: 99fa2ba7086d8b3f4140f089f88f59f4
SHA-256: e6a0ce4134c6a3d28dd5d24a4110eb98e8915220cab6c82af40f6eadce629722
gstreamer-plugins-devel-0.8.5-1.EL.3.i386.rpm
File outdated by:  RHSA-2011:1264
    MD5: 3272af4ed8afc230bb399896abee56cd
SHA-256: a2040aa0835f9040059d47573cf00514835c468c418f8c14a01fbfb77494d9ec
 
IA-64:
gstreamer-plugins-0.8.5-1.EL.3.ia64.rpm
File outdated by:  RHSA-2011:1264
    MD5: 77dcdc2a54d78d32892f2953f858b3b5
SHA-256: ea750dcdf6885c11e8a4916fe78083e863225efe5c0cdb285ff6832182efc578
gstreamer-plugins-devel-0.8.5-1.EL.3.ia64.rpm
File outdated by:  RHSA-2011:1264
    MD5: 1e027e9c5cebb961aa3279418aca8b0e
SHA-256: 73f9b55cd8e7c5f771b4495a83db1d4074f6115653b72ade80973c71106a8d9f
 
PPC:
gstreamer-plugins-0.8.5-1.EL.3.ppc.rpm
File outdated by:  RHSA-2011:1264
    MD5: 8086a3d9fd38ff1945c334e8a0ce8a26
SHA-256: 15209791db2661dbe2872809b63f2d1162deca431e0b94bd4ec2f197020d2a92
gstreamer-plugins-devel-0.8.5-1.EL.3.ppc.rpm
File outdated by:  RHSA-2011:1264
    MD5: faeed976f9afb9a082ac17bd769e7272
SHA-256: 67b08364d5b90424d513d3bd9c5eaee9ee0643f7e69056d8d97baf0482e8c4ed
 
s390:
gstreamer-plugins-0.8.5-1.EL.3.s390.rpm
File outdated by:  RHSA-2011:1264
    MD5: d710421b1101ff1c15908b89e618f112
SHA-256: aece1c542080681b8bf19abe6407dac74728dc625a562323fec0f6232e74ca3d
gstreamer-plugins-devel-0.8.5-1.EL.3.s390.rpm
File outdated by:  RHSA-2011:1264
    MD5: 95dda0a983b1cb6c50011eedf5cbc742
SHA-256: 6f3fec54fec4ad1c351f581989143c46baa9bfb15a5a489e7469eb1836bc59a3
 
s390x:
gstreamer-plugins-0.8.5-1.EL.3.s390x.rpm
File outdated by:  RHSA-2011:1264
    MD5: a57d6223a1486b411fdd3021f819c37d
SHA-256: 9d65248a3798e0fd3357e5752a25ae5bf1e7b557dd22c69a5ac3882b1ce6c40b
gstreamer-plugins-devel-0.8.5-1.EL.3.s390x.rpm
File outdated by:  RHSA-2011:1264
    MD5: 869d8504df70239b62a48153a27e8c2e
SHA-256: fdff0cadc93d046b36dae4921bcdd10a28b941366d4836973c62ab664a82cf98
 
x86_64:
gstreamer-plugins-0.8.5-1.EL.3.x86_64.rpm
File outdated by:  RHSA-2011:1264
    MD5: 2c5868a9c7fae56c57b6e6c77e19a51b
SHA-256: 88d62b96f925016d1a062b9f2c6a9b705ea01e005194d55134d527d5cc29095e
gstreamer-plugins-devel-0.8.5-1.EL.3.x86_64.rpm
File outdated by:  RHSA-2011:1264
    MD5: 6f185249017b780ade27020ef7b946fe
SHA-256: 210073fa2fdbc6fcd975e590bd954285aff38a2541810fae90360dc7deb724e6
 
Red Hat Enterprise Linux AS (v. 4.8.z)

SRPMS:
gstreamer-plugins-0.8.5-1.EL.3.src.rpm
File outdated by:  RHSA-2011:1264
    MD5: 688ea081bc8a9281c5a1132a85218ed9
SHA-256: 6224b7d9a1572a98d9322948aaf7402e51dbf6e689a310bad898c7a4802092fb
 
IA-32:
gstreamer-plugins-0.8.5-1.EL.3.i386.rpm     MD5: 99fa2ba7086d8b3f4140f089f88f59f4
SHA-256: e6a0ce4134c6a3d28dd5d24a4110eb98e8915220cab6c82af40f6eadce629722
gstreamer-plugins-devel-0.8.5-1.EL.3.i386.rpm     MD5: 3272af4ed8afc230bb399896abee56cd
SHA-256: a2040aa0835f9040059d47573cf00514835c468c418f8c14a01fbfb77494d9ec
 
IA-64:
gstreamer-plugins-0.8.5-1.EL.3.ia64.rpm     MD5: 77dcdc2a54d78d32892f2953f858b3b5
SHA-256: ea750dcdf6885c11e8a4916fe78083e863225efe5c0cdb285ff6832182efc578
gstreamer-plugins-devel-0.8.5-1.EL.3.ia64.rpm     MD5: 1e027e9c5cebb961aa3279418aca8b0e
SHA-256: 73f9b55cd8e7c5f771b4495a83db1d4074f6115653b72ade80973c71106a8d9f
 
PPC:
gstreamer-plugins-0.8.5-1.EL.3.ppc.rpm     MD5: 8086a3d9fd38ff1945c334e8a0ce8a26
SHA-256: 15209791db2661dbe2872809b63f2d1162deca431e0b94bd4ec2f197020d2a92
gstreamer-plugins-devel-0.8.5-1.EL.3.ppc.rpm     MD5: faeed976f9afb9a082ac17bd769e7272
SHA-256: 67b08364d5b90424d513d3bd9c5eaee9ee0643f7e69056d8d97baf0482e8c4ed
 
s390:
gstreamer-plugins-0.8.5-1.EL.3.s390.rpm     MD5: d710421b1101ff1c15908b89e618f112
SHA-256: aece1c542080681b8bf19abe6407dac74728dc625a562323fec0f6232e74ca3d
gstreamer-plugins-devel-0.8.5-1.EL.3.s390.rpm     MD5: 95dda0a983b1cb6c50011eedf5cbc742
SHA-256: 6f3fec54fec4ad1c351f581989143c46baa9bfb15a5a489e7469eb1836bc59a3
 
s390x:
gstreamer-plugins-0.8.5-1.EL.3.s390x.rpm     MD5: a57d6223a1486b411fdd3021f819c37d
SHA-256: 9d65248a3798e0fd3357e5752a25ae5bf1e7b557dd22c69a5ac3882b1ce6c40b
gstreamer-plugins-devel-0.8.5-1.EL.3.s390x.rpm     MD5: 869d8504df70239b62a48153a27e8c2e
SHA-256: fdff0cadc93d046b36dae4921bcdd10a28b941366d4836973c62ab664a82cf98
 
x86_64:
gstreamer-plugins-0.8.5-1.EL.3.x86_64.rpm     MD5: 2c5868a9c7fae56c57b6e6c77e19a51b
SHA-256: 88d62b96f925016d1a062b9f2c6a9b705ea01e005194d55134d527d5cc29095e
gstreamer-plugins-devel-0.8.5-1.EL.3.x86_64.rpm     MD5: 6f185249017b780ade27020ef7b946fe
SHA-256: 210073fa2fdbc6fcd975e590bd954285aff38a2541810fae90360dc7deb724e6
 
Red Hat Enterprise Linux ES (v. 4)

SRPMS:
gstreamer-plugins-0.8.5-1.EL.3.src.rpm
File outdated by:  RHSA-2011:1264
    MD5: 688ea081bc8a9281c5a1132a85218ed9
SHA-256: 6224b7d9a1572a98d9322948aaf7402e51dbf6e689a310bad898c7a4802092fb
 
IA-32:
gstreamer-plugins-0.8.5-1.EL.3.i386.rpm
File outdated by:  RHSA-2011:1264
    MD5: 99fa2ba7086d8b3f4140f089f88f59f4
SHA-256: e6a0ce4134c6a3d28dd5d24a4110eb98e8915220cab6c82af40f6eadce629722
gstreamer-plugins-devel-0.8.5-1.EL.3.i386.rpm
File outdated by:  RHSA-2011:1264
    MD5: 3272af4ed8afc230bb399896abee56cd
SHA-256: a2040aa0835f9040059d47573cf00514835c468c418f8c14a01fbfb77494d9ec
 
IA-64:
gstreamer-plugins-0.8.5-1.EL.3.ia64.rpm
File outdated by:  RHSA-2011:1264
    MD5: 77dcdc2a54d78d32892f2953f858b3b5
SHA-256: ea750dcdf6885c11e8a4916fe78083e863225efe5c0cdb285ff6832182efc578
gstreamer-plugins-devel-0.8.5-1.EL.3.ia64.rpm
File outdated by:  RHSA-2011:1264
    MD5: 1e027e9c5cebb961aa3279418aca8b0e
SHA-256: 73f9b55cd8e7c5f771b4495a83db1d4074f6115653b72ade80973c71106a8d9f
 
x86_64:
gstreamer-plugins-0.8.5-1.EL.3.x86_64.rpm
File outdated by:  RHSA-2011:1264
    MD5: 2c5868a9c7fae56c57b6e6c77e19a51b
SHA-256: 88d62b96f925016d1a062b9f2c6a9b705ea01e005194d55134d527d5cc29095e
gstreamer-plugins-devel-0.8.5-1.EL.3.x86_64.rpm
File outdated by:  RHSA-2011:1264
    MD5: 6f185249017b780ade27020ef7b946fe
SHA-256: 210073fa2fdbc6fcd975e590bd954285aff38a2541810fae90360dc7deb724e6
 
Red Hat Enterprise Linux ES (v. 4.8.z)

SRPMS:
gstreamer-plugins-0.8.5-1.EL.3.src.rpm
File outdated by:  RHSA-2011:1264
    MD5: 688ea081bc8a9281c5a1132a85218ed9
SHA-256: 6224b7d9a1572a98d9322948aaf7402e51dbf6e689a310bad898c7a4802092fb
 
IA-32:
gstreamer-plugins-0.8.5-1.EL.3.i386.rpm     MD5: 99fa2ba7086d8b3f4140f089f88f59f4
SHA-256: e6a0ce4134c6a3d28dd5d24a4110eb98e8915220cab6c82af40f6eadce629722
gstreamer-plugins-devel-0.8.5-1.EL.3.i386.rpm     MD5: 3272af4ed8afc230bb399896abee56cd
SHA-256: a2040aa0835f9040059d47573cf00514835c468c418f8c14a01fbfb77494d9ec
 
IA-64:
gstreamer-plugins-0.8.5-1.EL.3.ia64.rpm     MD5: 77dcdc2a54d78d32892f2953f858b3b5
SHA-256: ea750dcdf6885c11e8a4916fe78083e863225efe5c0cdb285ff6832182efc578
gstreamer-plugins-devel-0.8.5-1.EL.3.ia64.rpm     MD5: 1e027e9c5cebb961aa3279418aca8b0e
SHA-256: 73f9b55cd8e7c5f771b4495a83db1d4074f6115653b72ade80973c71106a8d9f
 
x86_64:
gstreamer-plugins-0.8.5-1.EL.3.x86_64.rpm     MD5: 2c5868a9c7fae56c57b6e6c77e19a51b
SHA-256: 88d62b96f925016d1a062b9f2c6a9b705ea01e005194d55134d527d5cc29095e
gstreamer-plugins-devel-0.8.5-1.EL.3.x86_64.rpm     MD5: 6f185249017b780ade27020ef7b946fe
SHA-256: 210073fa2fdbc6fcd975e590bd954285aff38a2541810fae90360dc7deb724e6
 
Red Hat Enterprise Linux WS (v. 4)

SRPMS:
gstreamer-plugins-0.8.5-1.EL.3.src.rpm
File outdated by:  RHSA-2011:1264
    MD5: 688ea081bc8a9281c5a1132a85218ed9
SHA-256: 6224b7d9a1572a98d9322948aaf7402e51dbf6e689a310bad898c7a4802092fb
 
IA-32:
gstreamer-plugins-0.8.5-1.EL.3.i386.rpm
File outdated by:  RHSA-2011:1264
    MD5: 99fa2ba7086d8b3f4140f089f88f59f4
SHA-256: e6a0ce4134c6a3d28dd5d24a4110eb98e8915220cab6c82af40f6eadce629722
gstreamer-plugins-devel-0.8.5-1.EL.3.i386.rpm
File outdated by:  RHSA-2011:1264
    MD5: 3272af4ed8afc230bb399896abee56cd
SHA-256: a2040aa0835f9040059d47573cf00514835c468c418f8c14a01fbfb77494d9ec
 
IA-64:
gstreamer-plugins-0.8.5-1.EL.3.ia64.rpm
File outdated by:  RHSA-2011:1264
    MD5: 77dcdc2a54d78d32892f2953f858b3b5
SHA-256: ea750dcdf6885c11e8a4916fe78083e863225efe5c0cdb285ff6832182efc578
gstreamer-plugins-devel-0.8.5-1.EL.3.ia64.rpm
File outdated by:  RHSA-2011:1264
    MD5: 1e027e9c5cebb961aa3279418aca8b0e
SHA-256: 73f9b55cd8e7c5f771b4495a83db1d4074f6115653b72ade80973c71106a8d9f
 
x86_64:
gstreamer-plugins-0.8.5-1.EL.3.x86_64.rpm
File outdated by:  RHSA-2011:1264
    MD5: 2c5868a9c7fae56c57b6e6c77e19a51b
SHA-256: 88d62b96f925016d1a062b9f2c6a9b705ea01e005194d55134d527d5cc29095e
gstreamer-plugins-devel-0.8.5-1.EL.3.x86_64.rpm
File outdated by:  RHSA-2011:1264
    MD5: 6f185249017b780ade27020ef7b946fe
SHA-256: 210073fa2fdbc6fcd975e590bd954285aff38a2541810fae90360dc7deb724e6
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

497154 - CVE-2006-4192 libmodplug: Integer overflow when reading samples of AMF files
695420 - CVE-2011-1574 libmodplug: ReadS3M stack overflow vulnerability


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/