-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3225-1 security@debian.org http://www.debian.org/security/ Moritz Muehlenhoff April 15, 2015 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : gst-plugins-bad0.10 CVE ID : CVE-2015-0797 Aki Helin discovered a buffer overflow in the GStreamer plugin for MP4 playback, which could lead in the execution of arbitrary code. For the stable distribution (wheezy), this problem has been fixed in version 0.10.23-7.1+deb7u2. For the unstable distribution (sid), this problem will be fixed soon. We recommend that you upgrade your gst-plugins-bad0.10 packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBAgAGBQJVLoHwAAoJEBDCk7bDfE42FUsP/3gPEPyf1DdQUOB4rrK4TxN4 X0asIopOxyjZpB/jMFIPmtrLGr2kH4g6E0G3b/TuIiX+zd3Z0h+xENC5nOm5lRRY rP0G0DszPprirt6TTij7rwiGZPnDX/m0vQbF4G4SEh46OfT8z64h1fK0q8HcKp5p txdEMXQrGyj49BZsyFEWd+oIyJygqtDcGRT5aX5Rbc7+x+sGVlvNhSBLU0Yef3tC u/fEGtXdoteFvXwCIIL/DZKrnPVq3iJXgR7SnkLtTIe85gdnFrDcqimZa4BfDzmv MP6KcM5Q84HG1W7+RngSfTOjGp+pOh+OCEE+5Jlr7QIO4EjO7TTPV12zL2rkxRRB NMc/GwRj5ZV7qQaVJjjrk/oYX5HE45/30JZXFg7O2f6YMWC8j9snvT2RbzNz25JF xsLHWTIfTaVQPUDnBw+13a7Q0YMaVjMrnhc9r/bAzh0Rp6M+5x5B53E2hFmxZ1Ry zIA7XRd+1sxhdVFNSUEMJ+cOROxOxN6qao7EqFUrdYykT3wfTnxCeLIQVHryLrqU Fm+BKhz5lzTn+I+SeP0r/Vxy6qVPno2c01PeBfVw6sIabx4eEuGkuteErFHFQtxH XACPeE+vMPODfrIqbCHjxPMDG9FAI6zOShHkqVkg2pnA/xCddtg2Z1QFGbn73cEv fhUFOUBUKzZOG1mA9XxR =Ky+/ -----END PGP SIGNATURE-----