Description: | Description:
The remote host is missing an update to gst-plugins-good0.10 announced via advisory USN-611-3.
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS Ubuntu 7.04 Ubuntu 7.10 Ubuntu 8.04 LTS
This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu.
Details follow:
USN-611-1 fixed a vulnerability in Speex. This update provides the corresponding update for GStreamer Good Plugins.
Original advisory details:
It was discovered that Speex did not properly validate its input when processing Speex file headers. If a user or automated system were tricked into opening a specially crafted Speex file, an attacker could create a denial of service in applications linked against Speex or possibly execute arbitrary code as the user invoking the program.
Solution: The problem can be corrected by upgrading your system to the following package versions:
Ubuntu 6.06 LTS: gstreamer0.10-plugins-good 0.10.3-0ubuntu4.1
Ubuntu 7.04: gstreamer0.10-plugins-good 0.10.5-1ubuntu2.1
Ubuntu 7.10: gstreamer0.10-plugins-good 0.10.6-0ubuntu4.1
Ubuntu 8.04 LTS: gstreamer0.10-plugins-good 0.10.7-3ubuntu0.1
In general, a standard system upgrade is sufficient to effect the necessary changes.
http://www.securityspace.com/smysecure/catid.html?in=USN-611-3
Risk factor : Critical
CVSS Score: 9.3
|