QID 750088
QID 750088: SUSE Enterprise Linux Security Update for gstreamer, gstreamer-plugins-bad, gstreamer-plugins-base, gstreamer-plugins-good, gstreamer-plugins-ugly (SUSE-SU-2021:1819-1)
This update for gstreamer, gstreamer-plugins-bad, gstreamer-plugins-base, gstreamer-plugins-good, gstreamer-plugins-ugly fixes the following issues: gstreamer was updated to version 1.16.3 (bsc#1181255): - delay creation of threadpools - bin: fix `deep-element-removed` log message - buffer: fix meta sequence number fallback on rpi - bufferlist: foreach: always remove as parent if buffer is changed - bus: make setting/replacing/clearing the sync handler thread-safe - elementfactory: fix missing features in case a feature moves to another filename - element: when removing a ghost pad also unset its target - meta: intern registered impl string - registry: use a toolchain-specific registry file on windows - systemclock: invalid internal time calculation causes non-increasing clock time on windows - value: don't write to `const char *` - value: fix segfault comparing empty gvaluearrays - revert floating enforcing - aggregator: fix iteration direction in skip_buffers - sparsefile: fix possible crash when seeking - baseparse: cache fix - baseparse: fix memory leak when subclass skips whole input buffer - baseparse: set the private duration before posting a duration-changed message - basetransform: allow not passthrough if generate_output is implemented - identity: fix a minor leak using meta_str - queue: protect against lost wakeups for iterm_del condition - queue2: avoid races when posting buffering messages - queue2: fix missing/dropped buffering messages at startup - identity: unblock condition variable on flush_start - check: use `g_thread_yield()` instead of `g_usleep(1)` - tests: use cpu_family for arch checks - gst-launch: follow up to missing `s/g_print/gst_print/g` - gst-inspect: add define guard for `g_log_writer_supports_color()` - gst-launch: go back down to `gst_state_null` in one step.
- opencv: allow compilation against 4.2.x - proxysink: event_function needs to handle the event when it is disconnecetd from proxysrc - vulkan: drop use of vk_result_begin_range - wasapi: added missing lock release in case of error in gst_wasapi_xxx_reset - wasapi: fix possible deadlock while downwards state change - waylandsink: clear window when pipeline is stopped - webrtc: support non-trickle ice candidates in the sdp - webrtc: unmap all non-binary buffers received via the datachannel - meson: build with neon 0.31 - drop upstream fixed patch: gstreamer-h264parser-fix-overflow.patch - h264parser: guard against ref_pic_markings overflow (bsc#1181255 cve-2021-3185) - disable the kate/libtiger plugin.
kate streams for karaoke are not used anymore, and the source tarball for libtiger is no longer available upstream. (
- typefind: consider mpeg-ps psm to be a pes type - uridecodebin3: default to non-0 buffer-size and buffer-duration, otherwise it could potentially cause big memory allocations over time - videoaggregator: don't configure null chroma-site/colorimetry - videorate/videoscale/audioresample: ensure that the caps returned from... - build: replace bashisms in configure for wayland and gles3
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Successful exploitation allows attacker to compromise the system.
- SUSE-SU-2021:1819-1 -
lists.suse.com/pipermail/sle-security-updates/2021-June/008904.html
CVEs related to QID 750088
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SUSE-SU-2021:1819-1 | SUSE Enterprise Linux |
|