Headline
RHSA-2022:7618: Red Hat Security Advisory: gstreamer1-plugins-good security update
An update for gstreamer1-plugins-good is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.
Related CVEs:
- CVE-2021-3497: gstreamer-plugins-good: Use-after-free in matroska demuxing
Skip to navigation Skip to main content
Utilities
- Subscriptions
- Downloads
- Containers
- Support Cases
Infrastructure and Management
- Red Hat Enterprise Linux
- Red Hat Virtualization
- Red Hat Identity Management
- Red Hat Directory Server
- Red Hat Certificate System
- Red Hat Satellite
- Red Hat Subscription Management
- Red Hat Update Infrastructure
- Red Hat Insights
- Red Hat Ansible Automation Platform
Cloud Computing
- Red Hat OpenShift
- Red Hat CloudForms
- Red Hat OpenStack Platform
- Red Hat OpenShift Container Platform
- Red Hat OpenShift Data Science
- Red Hat OpenShift Online
- Red Hat OpenShift Dedicated
- Red Hat Advanced Cluster Security for Kubernetes
- Red Hat Advanced Cluster Management for Kubernetes
- Red Hat Quay
- Red Hat CodeReady Workspaces
- Red Hat OpenShift Service on AWS
Storage
- Red Hat Gluster Storage
- Red Hat Hyperconverged Infrastructure
- Red Hat Ceph Storage
- Red Hat OpenShift Data Foundation
Runtimes
- Red Hat Runtimes
- Red Hat JBoss Enterprise Application Platform
- Red Hat Data Grid
- Red Hat JBoss Web Server
- Red Hat Single Sign On
- Red Hat support for Spring Boot
- Red Hat build of Node.js
- Red Hat build of Thorntail
- Red Hat build of Eclipse Vert.x
- Red Hat build of OpenJDK
- Red Hat build of Quarkus
Integration and Automation
- Red Hat Process Automation
- Red Hat Process Automation Manager
- Red Hat Decision Manager
All Products
Issued:
2022-11-08
Updated:
2022-11-08
RHSA-2022:7618 - Security Advisory
- Overview
- Updated Packages
Synopsis
Moderate: gstreamer1-plugins-good security update
Type/Severity
Security Advisory: Moderate
Red Hat Insights patch analysis
Identify and remediate systems affected by this advisory.
View affected systems
Topic
An update for gstreamer1-plugins-good is now available for Red Hat Enterprise Linux 8.
Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Description
GStreamer is a streaming media framework based on graphs of filters that operate on media data. The gstreamer1-plugins-good packages contain a collection of well-supported plug-ins of good quality and under the LGPL license.
Security Fix(es):
- gstreamer-plugins-good: Use-after-free in matroska demuxing (CVE-2021-3497)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.7 Release Notes linked from the References section.
Affected Products
- Red Hat Enterprise Linux for x86_64 8 x86_64
- Red Hat Enterprise Linux for IBM z Systems 8 s390x
- Red Hat Enterprise Linux for Power, little endian 8 ppc64le
- Red Hat Enterprise Linux for ARM 64 8 aarch64
Fixes
- BZ - 1945339 - CVE-2021-3497 gstreamer-plugins-good: Use-after-free in matroska demuxing
References
- https://access.redhat.com/security/updates/classification/#moderate
- https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.7_release_notes/index
Red Hat Enterprise Linux for x86_64 8
SRPM
gstreamer1-plugins-good-1.16.1-3.el8.src.rpm
SHA-256: cbc21f0fd74141fd4c9b85715fc8808be67596af30adda1f6c09f1e7740cf14e
x86_64
gstreamer1-plugins-good-1.16.1-3.el8.i686.rpm
SHA-256: bf22d4d061420d2181e2bbb4ed04e862bceb33f7f659a7bb805bcb77a6e9800a
gstreamer1-plugins-good-1.16.1-3.el8.x86_64.rpm
SHA-256: 43fab7de606d7423e63731d9b32dec540494c8758cc74f47c633cbbd3a3a46d3
gstreamer1-plugins-good-debuginfo-1.16.1-3.el8.i686.rpm
SHA-256: f69e11ac3d951c26606fbb7b4f9b333ce9c9814622b3b44ef94c795a8422f620
gstreamer1-plugins-good-debuginfo-1.16.1-3.el8.x86_64.rpm
SHA-256: 2db77872ce842981db58d384303e6fdeb8a497dff371643f0f5b01a686cf2eb8
gstreamer1-plugins-good-debugsource-1.16.1-3.el8.i686.rpm
SHA-256: 1374b06b568c6d543af287675476caac0bd770689430ddb195247f3cf1d9ab40
gstreamer1-plugins-good-debugsource-1.16.1-3.el8.x86_64.rpm
SHA-256: 0581bd2630a90c3b513fd4d097eb96d188aab3657cc3ae6b7fca4f5b5342bd03
gstreamer1-plugins-good-gtk-1.16.1-3.el8.i686.rpm
SHA-256: 692ff0260371e38856e92e27e4a60f1da8bfe71a414d6c469d32fe7926c01259
gstreamer1-plugins-good-gtk-1.16.1-3.el8.x86_64.rpm
SHA-256: b1684439338265b5f5987379f840f2b91197b377501e3939d9a0930478141456
gstreamer1-plugins-good-gtk-debuginfo-1.16.1-3.el8.i686.rpm
SHA-256: 327f12434ae796c7e47a90c4e59882332596a45a4ee2a49d1a87bcc81539bca2
gstreamer1-plugins-good-gtk-debuginfo-1.16.1-3.el8.x86_64.rpm
SHA-256: 058f469d837b8fbc6990271c72b7691514bbc335abbae5c7c87e463c60f9560a
Red Hat Enterprise Linux for IBM z Systems 8
SRPM
gstreamer1-plugins-good-1.16.1-3.el8.src.rpm
SHA-256: cbc21f0fd74141fd4c9b85715fc8808be67596af30adda1f6c09f1e7740cf14e
s390x
gstreamer1-plugins-good-1.16.1-3.el8.s390x.rpm
SHA-256: aac3b9255fbc96bca22848d1cc1cce76248f95499ef65bd3035691addae24a57
gstreamer1-plugins-good-debuginfo-1.16.1-3.el8.s390x.rpm
SHA-256: 72f6b8f66b42c20d35fcfdbd88b2c06da4cd1c910c43bff734a24da73c041d81
gstreamer1-plugins-good-debugsource-1.16.1-3.el8.s390x.rpm
SHA-256: 36480522e19222b2818d67df264ad1fb55b11835285c319dcda14b2d3e05a7e8
gstreamer1-plugins-good-gtk-1.16.1-3.el8.s390x.rpm
SHA-256: 859189b63b96f20e81a9a22f1716ecf16c35918cd997adb677c29b9d55df169b
gstreamer1-plugins-good-gtk-debuginfo-1.16.1-3.el8.s390x.rpm
SHA-256: a8185a242ba698bdd782b8ababfeae03268137d5b213b9bbbddb43b9e3960a5c
Red Hat Enterprise Linux for Power, little endian 8
SRPM
gstreamer1-plugins-good-1.16.1-3.el8.src.rpm
SHA-256: cbc21f0fd74141fd4c9b85715fc8808be67596af30adda1f6c09f1e7740cf14e
ppc64le
gstreamer1-plugins-good-1.16.1-3.el8.ppc64le.rpm
SHA-256: e7bf7915464e667992f304ad8f512bbdcf4961b024d645cf6bfc19aaee8f506b
gstreamer1-plugins-good-debuginfo-1.16.1-3.el8.ppc64le.rpm
SHA-256: 257e458c05f25a8eb72e100ccacff07c3a580b59366eede69c7e4b394fdcb64d
gstreamer1-plugins-good-debugsource-1.16.1-3.el8.ppc64le.rpm
SHA-256: a049dddf0e63860348bfdc35613a8235646b5aaffa89b1c033c519efd06072e4
gstreamer1-plugins-good-gtk-1.16.1-3.el8.ppc64le.rpm
SHA-256: 0cfc6b77a25d8fca5c7c97997aea450deaf43a06b4fb0024c614eeacbd4067ba
gstreamer1-plugins-good-gtk-debuginfo-1.16.1-3.el8.ppc64le.rpm
SHA-256: 34ce1017c8d684a3d1aeea1500c76d90ed3064a8483027d724bb2437561597d8
Red Hat Enterprise Linux for ARM 64 8
SRPM
gstreamer1-plugins-good-1.16.1-3.el8.src.rpm
SHA-256: cbc21f0fd74141fd4c9b85715fc8808be67596af30adda1f6c09f1e7740cf14e
aarch64
gstreamer1-plugins-good-1.16.1-3.el8.aarch64.rpm
SHA-256: 1819cce06ffc9a80916b35fa7c63eb606cca22ddbefb6d33c356fce9a3151c7e
gstreamer1-plugins-good-debuginfo-1.16.1-3.el8.aarch64.rpm
SHA-256: f2c39cafb7494e0a1b1b7323d25a7bb7785e2a5de3eef85bb6bcb13d2bd858a6
gstreamer1-plugins-good-debugsource-1.16.1-3.el8.aarch64.rpm
SHA-256: dc787cd4d29362ecc823ba2c959d77d9382477d1da8e64b3ca174f5aba86e127
gstreamer1-plugins-good-gtk-1.16.1-3.el8.aarch64.rpm
SHA-256: 7ce909861b34539b99716fd35954e13880045dd3fc5d83ffd05d66a8a0a7c475
gstreamer1-plugins-good-gtk-debuginfo-1.16.1-3.el8.aarch64.rpm
SHA-256: 1054281e281e26c15704065194bc9fb5bc6de7d4e892416e416c0e6286fc8bed
The Red Hat security contact is [email protected]. More contact details at https://access.redhat.com/security/team/contact/.
Related news
Red Hat Security Advisory 2022-7618-01 - GStreamer is a streaming media framework based on graphs of filters that operate on media data. The gstreamer1-plugins-good packages contain a collection of well-supported plug-ins of good quality and under the LGPL license. Issues addressed include a use-after-free vulnerability.
Gentoo Linux Security Advisory 202208-31 - Multiple vulnerabilities have been found in GStreamer and its plugins, the worst of which could result in arbitrary code execution. Versions less than 1.16.3 are affected.