Package Release Info

gstreamer-plugins-bad-1.20.1-150400.3.15.1

Update Info: SUSE-SLE-Module-Packagehub-Subpackages-15-SP4-2024-5
Available in Package Hub : 15 SP4 Subpackages Updates

platforms

AArch64
ppc64le
s390x
x86-64

subpackages

libgsttranscoder-1_0-0

Change Logs

* Thu Nov 02 2023 qzhao@suse.com
- Add gstreamer-plugins-bad-CVE-2023-44446.patch:
  Backporting 274551d4 from upstream, Store GstMXFDemuxEssenceTrack
  in their own fixed allocation.
  (CVE-2023-44446 bsc#1217213)
* Thu Sep 21 2023 qzhao@suse.com
- Add gstreamer-plugins-bad-CVE-2023-40475.patch
  Backporting 72742dee from upstream, Check number of channels for
  AES3 audio.
  (CVE-2023-40475 bsc#1215792)
Version: 1.20.1-150400.3.12.1
* Tue Oct 24 2023 qzhao@suse.com
- Add gstreamer-plugins-bad-CVE-2023-44429.patch:
  Backporting 1db83d3f from upstream, Clip tile rows and cols to 64
  as describe in AV1 specification.
  (CVE-2023-44429 bsc#1217211)
* Thu Sep 21 2023 qzhao@suse.com
- Add gstreamer-plugins-bad-CVE-2023-40474.patch:
  Backporting ce17e968 from upstream, Fix integer overflow causing
  out of bounds writes when handling invalid uncompressed video.
  (CVE-2023-40474 bsc#1215796)
* Tue Sep 19 2023 qzhao@suse.com
- Add gstreamer-plugins-bad-CVE-2023-40476.patch:
  Backporting ff91a3d8 from upstream, Fix possible overflow using
  max_sub_layers_minus1.
  (CVE-2023-40476 bsc#1215793)
* Sat Jun 24 2023 alarrosa@suse.com
- Add gstreamer-plugins-bad-CVE-2023-37329.patch:
  Backport 7ed446dc,0dabf0eb from upstream, Fix a heap overwrite
  in PGS subtitle overlay decoder which might trigger a crash or
  remote code execution.
  (CVE-2023-37329 bsc#1213126)
* Fri Feb 19 2021 zcjia@suse.com
- Update to version 1.16.3 (bsc#1181255 CVE-2021-3185):
  - amcvideodec: fix sync meta copying not taking a reference
  - audiobuffersplit: Perform discont tracking on running time
  - audiobuffersplit: Specify in the template caps that only interleaved audio is supported
  - audiobuffersplit: Unset DISCONT flag if not discontinuous
  - autoconvert: Fix lock-less exchange or free condition
  - autoconvert: fix compiler warnings with g_atomic on recent GLib versions
  - avfvideosrc: element requests camera permissions even with capture-screen property is true
  - codecparsers: h264parser: guard against ref_pic_markings overflow
  - dtlsconnection: Avoid segmentation fault when no srtp capabilities are negotiated
  - dtls/connection: fix EOF handling with openssl 1.1.1e
  - fdkaacdec: add support for mpegversion=2
  - hls: Check nettle version to ensure AES128 support
  - ipcpipeline: Rework compiler checks
  - interlace: Increment phase_index before checking if we're at the end of the phase
  - lv2: Make it build with -fno-common
  - h264parser: Do not allocate too large size of memory for registered user data SEI
  - ladspa: fix unbounded integer properties
  - modplug: avoid division by zero
  - msdkdec: Fix GstMsdkContext leak
  - msdkenc: fix leaks on windows
  - musepackdec: Don't fail all queries if no sample rate is known yet
  - openslessink: Allow openslessink to handle 48kHz streams.
  - opencv: allow compilation against 4.2.x
  - proxysink: event_function needs to handle the event when it is disconnecetd from proxysrc
  - vulkan: Drop use of VK_RESULT_BEGIN_RANGE
  - wasapi: added missing lock release in case of error in gst_wasapi_xxx_reset
  - wasapi: Fix possible deadlock while downwards state change
  - waylandsink: Clear window when pipeline is stopped
  - webrtc: Support non-trickle ICE candidates in the SDP
  - webrtc: Unmap all non-binary buffers received via the datachannel
  - meson: build with neon 0.31
- Drop upstream fixed patch: gstreamer-h264parser-fix-overflow.patch