SUSE-SU-2017:1010-1

Advisory lineage Upstream: 5 Downstream: 0
Published: 13 Apr 2017, 09:59
Last modified:04 Feb 2026, 04:23

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

13 Apr 2017, 09:59
Published
Vulnerability first disclosed
04 Feb 2026, 04:23
Last Modified
Vulnerability information updated

Description

Security update for gstreamer-plugins-good This update for gstreamer-plugins-good fixes the following issues: - A crafted aac audio file could have caused an invalid read and thus corruption or denial of service (bsc#1024014, CVE-2016-10198) - A crafted mp4 file could have caused an invalid read and thus corruption or denial of service (bsc#1024017, CVE-2016-10199) - A crafted avi file could have caused an invalid read and thus corruption or denial of service (bsc#1024034, CVE-2017-5840) - A crafted AVI file with metadata tag entries (ncdt) could have caused invalid read access and thus corruption or denial of service (bsc#1024030, CVE-2017-5841) - A crafted avi file could have caused an invalid read access resulting in denial of service (bsc#1024062, CVE-2017-5845)

Affected Systems

  • susegstreamer-plugins-good&distro=SUSE Linux Enterprise Desktop 12 SP2

    < 1.8.3-12.12

  • susegstreamer-plugins-good&distro=SUSE Linux Enterprise Server 12 SP2

    < 1.8.3-12.12

  • susegstreamer-plugins-good&distro=SUSE Linux Enterprise Server for Raspberry Pi 12 SP2

    < 1.8.3-12.12

  • susegstreamer-plugins-good&distro=SUSE Linux Enterprise Server for SAP Applications 12 SP2

    < 1.8.3-12.12

References (11)