The vendor explicitly identifies these products or versions as containing the fix.
- gstreamer1-plugins-ugly-free-0:1.24.11-1.el10_0.2.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- gstreamer1-plugins-ugly-free-0:1.24.11-1.el10_0.2.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- gstreamer1-plugins-ugly-free-0:1.24.11-1.el10_0.2.src as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- gstreamer1-plugins-ugly-free-0:1.24.11-1.el10_0.2.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- gstreamer1-plugins-ugly-free-debuginfo-0:1.24.11-1.el10_0.2.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- gstreamer1-plugins-ugly-free-debuginfo-0:1.24.11-1.el10_0.2.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- gstreamer1-plugins-ugly-free-debuginfo-0:1.24.11-1.el10_0.2.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- gstreamer1-plugins-ugly-free-debugsource-0:1.24.11-1.el10_0.2.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- gstreamer1-plugins-ugly-free-debugsource-0:1.24.11-1.el10_0.2.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- gstreamer1-plugins-ugly-free-debugsource-0:1.24.11-1.el10_0.2.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- gstreamer1-plugins-ugly-free-0:1.26.7-2.el10_2.1.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- gstreamer1-plugins-ugly-free-0:1.26.7-2.el10_2.1.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
- Summary
- A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a RealMedia file containing a specially crafted FILEINFO metadata section, the demuxer parses variable-name and variable-value pairs using re_skip_pascal_string() without validating that offsets remain within the mapped buffer. Additionally, the element count controlling the parsing loop is read from attacker-controlled data without validation, which can cause an infinite loop. A crafted RealMedia file can cause the application to crash, hang, or potentially read limited adjacent memory contents.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
