From fac3cca7b09fafae7ba42b2738c08b28d5e48e9f5e557b57ac12a99b200c623a Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Bj=C3=B8rn=20Lie?= Date: Sun, 3 Sep 2023 12:58:18 +0000 Subject: [PATCH] Accepting request 1108451 from home:alarrosa:branches:multimedia:libs The PGS parsing buffer overflow (CVE-2023-37329) doesn't belong to gstreamer-plugins-base as it affects only gstreamer-plugins-bad (see https://gstreamer.freedesktop.org/security/sa-2023-0003.html). It's already mentioned in the gstreamer-plugins-bad changelog. OBS-URL: https://build.opensuse.org/request/show/1108451 OBS-URL: https://build.opensuse.org/package/show/multimedia:libs/gstreamer-plugins-base?expand=0&rev=204 --- gstreamer-plugins-base.changes | 2 -- 1 file changed, 2 deletions(-) diff --git a/gstreamer-plugins-base.changes b/gstreamer-plugins-base.changes index 83f4e7e..6bff656 100644 --- a/gstreamer-plugins-base.changes +++ b/gstreamer-plugins-base.changes @@ -44,8 +44,6 @@ Mon Jun 26 14:18:54 UTC 2023 - Bjørn Lie + video-blend: Fix linking error with C++. + Fixes FLAC file parsing integer overflow remote code execution vulnerability (bsc#1213128, CVE-2023-37327) - + Fixes PGS file parsing heap-based buffer overflow remote code - execution vulnerability (bsc#1213126, CVE-2023-37329) - Rebase reduce-required-meson.patch. -------------------------------------------------------------------