USN-3958-1: GStreamer Base Plugins vulnerability
29 April 2019
GStreamer Base Plugins could be made to crash or run programs if it received specially crafted network traffic.
Releases
Packages
- gst-plugins-base0.10 - GStreamer plugins
- gst-plugins-base1.0 - GStreamer plugins
Details
It was discovered that GStreamer Base Plugins did not correctly handle
certain malformed RTSP streams. If a user were tricked into opening a
crafted RTSP stream with a GStreamer application, an attacker could cause a
denial of service via application crash, or possibly execute arbitrary
code.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 18.10
Ubuntu 18.04
Ubuntu 16.04
In general, a standard system update will make all the necessary changes.