gst-plugins-bad1.0 1.22.4-1ubuntu1.1 source package in Ubuntu

Changelog

gst-plugins-bad1.0 (1.22.4-1ubuntu1.1) mantic-security; urgency=medium

  * SECURITY UPDATE: integer overflow in MXF file handling
    - debian/patches/CVE-2023-40474.patch: fix integer overflow causing out
      of bounds writes when handling invalid uncompressed video in
      gst/mxf/mxfup.c.
    - CVE-2023-40474
  * SECURITY UPDATE: integer overflow in MXF file handling
    - debian/patches/CVE-2023-40475.patch: check number of channels for
      AES3 audio in gst/mxf/mxfd10.c.
    - CVE-2023-40475
  * SECURITY UPDATE: integer overflow in H.265 video parser
    - debian/patches/CVE-2023-40476.patch: fix possible overflow using
      max_sub_layers_minus1 in gst-libs/gst/codecparsers/gsth265parser.c.
    - CVE-2023-40476
  * SECURITY UPDATE: AV1 codec parser buffer overflow
    - debian/patches/CVE-2023-44429.patch: clip max tile rows and cols
      values in gst-libs/gst/codecparsers/gstav1parser.c.
    - CVE-2023-44429
  * SECURITY UPDATE: MXF demuxer use-after-free
    - debian/patches/CVE-2023-44446.patch: store GstMXFDemuxEssenceTrack in
      their own fixed allocation in gst/mxf/mxfdemux.*.
    - CVE-2023-44446

 -- Marc Deslauriers <email address hidden>  Tue, 28 Nov 2023 11:29:21 -0500

Upload details

Uploaded by:
Marc Deslauriers
Uploaded to:
Mantic
Original maintainer:
Ubuntu Developers
Architectures:
any
Section:
libs
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section
Mantic updates universe libs
Mantic security universe libs

Downloads

File Size SHA-256 Checksum
gst-plugins-bad1.0_1.22.4.orig.tar.xz 5.3 MiB eaaf53224565eaabd505ca39c6d5769719b45795cf532ce1ceb60e1b2ebe99ac
gst-plugins-bad1.0_1.22.4.orig.tar.xz.asc 833 bytes 3cbb6c2c66f6add4f98e3defd9f16532ecc535ad1a1cafb191093962bed7a9ec
gst-plugins-bad1.0_1.22.4-1ubuntu1.1.debian.tar.xz 49.2 KiB 85f26f5d916c73b57c63d2cca86c61006a54053b6b09f1a494de116642539b74
gst-plugins-bad1.0_1.22.4-1ubuntu1.1.dsc 5.9 KiB d93604c5e8e816dc9f7a8af9f3763b5b34841d7c5e6adb88882e73e324c7162f

View changes file

Binary packages built by this source

gir1.2-gst-plugins-bad-1.0: GObject introspection data for the GStreamer libraries from the "bad" set

 GStreamer is a streaming media framework, based on graphs of filters
 which operate on media data. Applications using this library can do
 anything from real-time sound processing to playing videos, and just
 about anything else media-related. Its plugin-based architecture means
 that new data types or processing capabilities can be added simply by
 installing new plug-ins.
 .
 GStreamer Bad Plug-ins is a set of plug-ins that aren't up to par compared
 to the rest. They might be close to being good quality, but they're missing
 something - be it a good code review, some documentation, a set of tests, a
 real live maintainer, or some actual wide use.
 .
 This package contains introspection data for the GStreamer libraries from
 the "bad" set. It can be used by packages using the GIRepository format to
 generate dynamic bindings.

gstreamer1.0-opencv: GStreamer OpenCV plugins

 GStreamer is a streaming media framework, based on graphs of filters
 which operate on media data. Applications using this library can do
 anything from real-time sound processing to playing videos, and just
 about anything else media-related. Its plugin-based architecture means
 that new data types or processing capabilities can be added simply by
 installing new plug-ins.
 .
 GStreamer Bad Plug-ins is a set of plug-ins that aren't up to par compared
 to the rest. They might be close to being good quality, but they're missing
 something - be it a good code review, some documentation, a set of tests, a
 real live maintainer, or some actual wide use.
 .
 This package contains the OpenCV plugins.

gstreamer1.0-opencv-dbgsym: debug symbols for gstreamer1.0-opencv
gstreamer1.0-plugins-bad: GStreamer plugins from the "bad" set

 GStreamer is a streaming media framework, based on graphs of filters
 which operate on media data. Applications using this library can do
 anything from real-time sound processing to playing videos, and just
 about anything else media-related. Its plugin-based architecture means
 that new data types or processing capabilities can be added simply by
 installing new plug-ins.
 .
 GStreamer Bad Plug-ins is a set of plug-ins that aren't up to par compared
 to the rest. They might be close to being good quality, but they're missing
 something - be it a good code review, some documentation, a set of tests, a
 real live maintainer, or some actual wide use.

gstreamer1.0-plugins-bad-apps: GStreamer helper programs from the "bad" set

 GStreamer is a streaming media framework, based on graphs of filters
 which operate on media data. Applications using this library can do
 anything from real-time sound processing to playing videos, and just
 about anything else media-related. Its plugin-based architecture means
 that new data types or processing capabilities can be added simply by
 installing new plug-ins.
 .
 This package contains helper programs from the "bad" set, a set of
 plug-ins that aren't up to par compared to the rest. They might be
 close to being good quality, but they're missing something - be it a
 good code review, some documentation, a set of tests, a real live
 maintainer, or some actual wide use.

gstreamer1.0-plugins-bad-apps-dbgsym: debug symbols for gstreamer1.0-plugins-bad-apps
gstreamer1.0-plugins-bad-dbgsym: debug symbols for gstreamer1.0-plugins-bad
libgstreamer-opencv1.0-0: GStreamer OpenCV libraries

 GStreamer is a streaming media framework, based on graphs of filters
 which operate on media data. Applications using this library can do
 anything from real-time sound processing to playing videos, and just
 about anything else media-related. Its plugin-based architecture means
 that new data types or processing capabilities can be added simply by
 installing new plug-ins.
 .
 GStreamer Bad Plug-ins is a set of plug-ins that aren't up to par compared
 to the rest. They might be close to being good quality, but they're missing
 something - be it a good code review, some documentation, a set of tests, a
 real live maintainer, or some actual wide use.
 .
 This package contains shared GStreamer libraries for OpenCV.

libgstreamer-opencv1.0-0-dbgsym: debug symbols for libgstreamer-opencv1.0-0
libgstreamer-plugins-bad1.0-0: GStreamer libraries from the "bad" set

 GStreamer is a streaming media framework, based on graphs of filters
 which operate on media data. Applications using this library can do
 anything from real-time sound processing to playing videos, and just
 about anything else media-related. Its plugin-based architecture means
 that new data types or processing capabilities can be added simply by
 installing new plug-ins.
 .
 GStreamer Bad Plug-ins is a set of plug-ins that aren't up to par compared
 to the rest. They might be close to being good quality, but they're missing
 something - be it a good code review, some documentation, a set of tests, a
 real live maintainer, or some actual wide use.
 .
 This package contains shared GStreamer libraries from the "bad" set. The API
 is not guaranteed to be stable.

libgstreamer-plugins-bad1.0-0-dbgsym: debug symbols for libgstreamer-plugins-bad1.0-0
libgstreamer-plugins-bad1.0-dev: GStreamer development files for libraries from the "bad" set

 GStreamer is a streaming media framework, based on graphs of filters
 which operate on media data. Applications using this library can do
 anything from real-time sound processing to playing videos, and just
 about anything else media-related. Its plugin-based architecture means
 that new data types or processing capabilities can be added simply by
 installing new plug-ins.
 .
 GStreamer Bad Plug-ins is a set of plug-ins that aren't up to par compared
 to the rest. They might be close to being good quality, but they're missing
 something - be it a good code review, some documentation, a set of tests, a
 real live maintainer, or some actual wide use.
 .
 This package contains development files for GStreamer libraries from the
 "bad" set. The API is not guaranteed to be stable.