Bug 20235 - gstreamer1.0 new security issue CVE-2017-5838
Summary: gstreamer1.0 new security issue CVE-2017-5838
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 5
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL: https://lwn.net/Vulnerabilities/713776/
Whiteboard: MGA5-64-OK advisory
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2017-02-02 12:14 CET by David Walser
Modified: 2017-08-24 23:19 CEST (History)
6 users (show)

See Also:
Source RPM: gstreamer1.0-1.4.3-2.mga5.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2017-02-02 12:14:55 CET
CVEs have been assigned for several security issues fixed in gstreamer 1.10.3:
http://openwall.com/lists/oss-security/2017/02/02/9

One of those is in the gstreamer core.  Mageia 5 may be affected.
Comment 1 Marja Van Waes 2017-02-02 16:02:33 CET
Assigning to the registered maintainer, but CC'ing all packagers collectively, in case the maintainer is unavailable.

CC: (none) => marja11, pkg-bugs
Assignee: bugsquad => fundawang

David Walser 2017-02-07 12:10:50 CET

URL: (none) => https://lwn.net/Vulnerabilities/713776/

David Walser 2017-02-21 12:27:49 CET

Assignee: fundawang => shlomif

Comment 2 David Walser 2017-04-20 12:02:17 CEST
openSUSE has issued an advisory for this on April 18:
https://lists.opensuse.org/opensuse-updates/2017-04/msg00058.html
Comment 3 Nicolas Lécureuil 2017-08-21 23:00:51 CEST
pushed in updates_testing
src.rpm:
        gstreamer1.0-1.4.3-2.1.mga5

CC: (none) => mageia
Assignee: shlomif => qa-bugs

Comment 4 David Walser 2017-08-21 23:09:13 CEST
Advisory:
========================

Updated gstreamer1.0 packages fix security vulnerability:

A crafted AVI file could have caused an invalid memory read, possibly causing
DoS or corruption (CVE-2017-5838).

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5838
https://lists.opensuse.org/opensuse-updates/2017-04/msg00058.html
========================

Updated packages in core/updates_testing:
========================
gstreamer1.0-tools-1.4.3-2.1.mga5
libgstreamer1.0_0-1.4.3-2.1.mga5
libgst-gir1.0-1.4.3-2.1.mga5
libgstreamer1.0-devel-1.4.3-2.1.mga5

from gstreamer1.0-1.4.3-2.1.mga5.src.rpm
Comment 5 PC LX 2017-08-24 13:52:23 CEST
Installed and tested without issues.

Tested using gst-play-1.0 to play dozens of video and audio files, including local and remote (http) files, using a variety of codecs.

$ uname -a
Linux marte 4.4.82-desktop-1.mga5 #1 SMP Sun Aug 13 18:03:58 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux
$ rpm -qa | grep gst.*1\.0 | sort
gstreamer1.0-libav-1.4.3-4.mga5
gstreamer1.0-plugins-bad-1.4.3-2.mga5.tainted
gstreamer1.0-plugins-base-1.4.3-2.2.mga5
gstreamer1.0-plugins-good-1.4.3-2.2.mga5
gstreamer1.0-plugins-ugly-1.4.3-2.mga5.tainted
gstreamer1.0-pulse-1.4.3-2.2.mga5
gstreamer1.0-soup-1.4.3-2.2.mga5
gstreamer1.0-tools-1.4.3-2.1.mga5
lib64gstbadbase1.0_0-1.4.3-2.mga5.tainted
lib64gstbadvideo1.0_0-1.4.3-2.mga5.tainted
lib64gstbasecamerabinsrc1.0_0-1.4.3-2.mga5.tainted
lib64gstcodecparsers1.0_0-1.4.3-2.mga5.tainted
lib64gstgl1.0_0-1.4.3-2.mga5.tainted
lib64gstmpegts1.0_0-1.4.3-2.mga5.tainted
lib64gstphotography1.0_0-1.4.3-2.mga5.tainted
lib64gstreamer1.0_0-1.4.3-2.1.mga5
lib64gstreamer1.0-devel-1.4.3-2.1.mga5
lib64gstreamer-plugins-base1.0_0-1.4.3-2.2.mga5
lib64gstreamer-plugins-base1.0-devel-1.4.3-2.2.mga5
lib64gsturidownloader1.0_0-1.4.3-2.mga5.tainted
lib64gstwayland1.0_0-1.4.3-2.mga5.tainted
lib64qtgstreamer1.0_0-1.2.0-2.mga5
lib64qtgstreamerutils1.0_0-1.2.0-2.mga5
packagekit-gstreamer-plugin-1.0.6-0.4.1.mga5

CC: (none) => mageia
Whiteboard: (none) => MGA5-64-OK

Comment 6 Lewis Smith 2017-08-24 22:09:37 CEST
Thanks PC_LX for this test.
Validating with just 1 good test as per current policy.

Keywords: (none) => validated_update
Whiteboard: MGA5-64-OK => MGA5-64-OK advisory
CC: (none) => lewyssmith, sysadmin-bugs

Comment 7 Mageia Robot 2017-08-24 23:19:15 CEST
An update for this issue has been pushed to the Mageia Updates repository.

http://advisories.mageia.org/MGASA-2017-0300.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.