oss-sec mailing list archives

Re: GStreamer 1.24.10 stable security bug-fix release


From: Alan Coopersmith <alan.coopersmith () oracle com>
Date: Fri, 3 Jan 2025 13:31:13 -0800

On 12/13/24 10:26, Alan Coopersmith wrote:
https://discourse.gstreamer.org/t/gstreamer-1-24-10-stable-bug-fix-release/3683
was posted on December 3, announcing:

    The GStreamer team is pleased to announce another bug fix release in the new
    stable 1.24 release series.

    This release only contains bug fixes and security fixes. It should be safe to
    upgrade from 1.24.x and we recommend you update at your earliest convenience.

     Highlights:

     - More than 40 security fixes across a wide range of elements following an
       audit by the GitHub Security Lab, including the MP4, Matroska, Ogg and WAV
       demuxers, subtitle parsers, image decoders, audio decoders and the id3v2
       tag parser.

The GitHub Security Lab posted a blog with more information and links to their
advisories at:
https://github.blog/security/vulnerability-research/uncovering-gstreamer-secrets/

--
        -Alan Coopersmith-                 alan.coopersmith () oracle com
         Oracle Solaris Engineering - https://blogs.oracle.com/solaris


Current thread: