gst-plugins-bad1.0.git
2 years agoSA-2023-0003
Maintainers of GStreamer packages [Sat, 22 Jul 2023 16:03:02 +0000 (17:03 +0100)]
SA-2023-0003

Gbp-Pq: Name SA-2023-0003.patch

2 years ago[PATCH] h2645parser: Catch overflows in AVC/HEVC NAL unit length calculations
Sebastian Dröge [Tue, 23 Mar 2021 17:19:14 +0000 (19:19 +0200)]
[PATCH] h2645parser: Catch overflows in AVC/HEVC NAL unit length calculations

Offset and size are stored as 32 bit guint and might overflow when
adding the nal_length_size, so let's avoid that.

For the size this would happen if the AVC/HEVC NAL unit size happens to
be stored in 4 bytes and is 4294967292 or higher, which is likely
corrupted data anyway.

For the offset this is something for the caller of these functions to
take care of but is unlikely to happen as it would require parsing on a
>4GB buffer.

Allowing these overflows causes all kinds of follow-up bugs in the
h2645parse elements, ranging from infinite loops and memory leaks to
potential memory corruptions.

Part-of: <https://gitlab.freedesktop.org/gstreamer/gst-plugins-bad/-/merge_requests/2103>

Gbp-Pq: Name 0001-h2645parser-Catch-overflows-in-AVC-HEVC-NAL-unit-length.patch

2 years ago_openexr-std-cxx11
Maintainers of GStreamer packages [Sat, 22 Jul 2023 16:03:02 +0000 (17:03 +0100)]
_openexr-std-cxx11

===================================================================

Gbp-Pq: Name 03_openexr-std-cxx11.patch

2 years ago[PATCH] codecparsers: h264parser: guard against ref_pic_markings overflow
Andrew Wesie [Fri, 16 Oct 2020 11:29:02 +0000 (12:29 +0100)]
[PATCH] codecparsers: h264parser: guard against ref_pic_markings overflow

Part-of: <https://gitlab.freedesktop.org/gstreamer/gst-plugins-bad/-/merge_requests/1703>

Gbp-Pq: Name 02_ref_pic_markings_overflow.patch

2 years agoTell libtool not to deduplicate linked libraries which causes problems in the case...
Iain Lane [Sat, 22 Jul 2023 16:03:02 +0000 (17:03 +0100)]
Tell libtool not to deduplicate linked libraries which causes problems in the case of circular deps. Force -lc to be added at the end.

Gbp-Pq: Name 01_fix-modplug-linking.patch

2 years agogst-plugins-bad1.0 (1.14.4-1+deb10u3) buster-security; urgency=high
Thorsten Alteholz [Sat, 22 Jul 2023 16:03:02 +0000 (17:03 +0100)]
gst-plugins-bad1.0 (1.14.4-1+deb10u3) buster-security; urgency=high

  * Non-maintainer upload by the LTS Team.
  * CVE-2023-37329
    SA-2023-0003: fix heap override

[dgit import unpatched gst-plugins-bad1.0 1.14.4-1+deb10u3]

2 years agoImport gst-plugins-bad1.0_1.14.4-1+deb10u3.debian.tar.xz
Thorsten Alteholz [Sat, 22 Jul 2023 16:03:02 +0000 (17:03 +0100)]
Import gst-plugins-bad1.0_1.14.4-1+deb10u3.debian.tar.xz

[dgit import tarball gst-plugins-bad1.0 1.14.4-1+deb10u3 gst-plugins-bad1.0_1.14.4-1+deb10u3.debian.tar.xz]

7 years agoImport gst-plugins-bad1.0_1.14.4.orig.tar.xz
Sebastian Dröge [Wed, 3 Oct 2018 10:57:59 +0000 (11:57 +0100)]
Import gst-plugins-bad1.0_1.14.4.orig.tar.xz

[dgit import orig gst-plugins-bad1.0_1.14.4.orig.tar.xz]