Arbitrary code execution via malformed SPC music file
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
game-music-emu (Debian) |
Fix Released
|
Unknown
|
|||
game-music-emu (Ubuntu) |
Fix Released
|
High
|
Unassigned |
Bug Description
Steps:
1. Ubuntu 16.04.1 LTS
2. Trying to play xcalc_ubuntu_
3. Totem found required plugin for playing "SNES-SPC700 Sound File Data decoder" which is in gstreamer1.
4. xcalc does not launched on music play or by Nautilus launch.
Ubuntu security team, please read blog post (see above link) and confirm (and fix) or refute zero-day vulnerability.
ProblemType: Bug
DistroRelease: Ubuntu 16.04
Package: gstreamer1.
ProcVersionSign
Uname: Linux 4.4.0-31-generic i686
ApportVersion: 2.20.1-0ubuntu2.1
Architecture: i386
CasperVersion: 1.376
CurrentDesktop: Unity
Date: Fri Dec 16 12:03:27 2016
LiveMediaBuild: Ubuntu 16.04.1 LTS "Xenial Xerus" - Release i386 (20160719)
ProcEnviron:
TERM=xterm-
PATH=(custom, no user)
XDG_RUNTIME_
LANG=en_US.UTF-8
SHELL=/bin/bash
SourcePackage: gst-plugins-bad1.0
UpgradeStatus: No upgrade log present (probably fresh install)
summary: |
- totem can't find required plugin for playing "SNES-SPC700 Sound File - Data decoder" which is in gstreamer1.0-plugins-bad + Plugin "SNES-SPC700 Sound File Data decoder" in gstreamer1.0-plugins-bad + may have security vulnerability |
description: | updated |
no longer affects: | gst-plugins-bad1.0 (Ubuntu) |
no longer affects: | totem (Ubuntu) |
Changed in game-music-emu (Ubuntu): | |
importance: | Undecided → High |
Changed in game-music-emu (Debian): | |
status: | Unknown → Fix Released |
summary: |
- Plugin "SNES-SPC700 Sound File Data decoder" in gstreamer1.0-plugins-bad - may have security vulnerability + Arbitrary code execution via malformed SPC music file |
We've released security updates to address this issue for all supported Ubuntu releases:
https:/ /launchpad. net/ubuntu/ +source/ game-music- emu/0.6. 0-3ubuntu0. 16.10.1 /launchpad. net/ubuntu/ +source/ game-music- emu/0.6. 0-3ubuntu0. 16.04.1 /launchpad. net/ubuntu/ +source/ game-music- emu/0.5. 5-2ubuntu0. 14.04.1 /launchpad. net/ubuntu/ +source/ game-music- emu/0.5. 5-2ubuntu0. 12.04.1
https:/
https:/
https:/
Please make sure that you've applied all security updates. Thanks!