As detailed by Chris Evans, the flic decoder contains a buffer overflow which can be exploited to cause arbitrary code execution as the user running gstreamer: https://scarybeastsecurity.blogspot.be/2016/11/0day-exploit-advancing-exploitation.html Fixes CVE-2016-9634, CVE-2016-9635 and CVE-2016-9636. add the upstream patches to fix this issue. Signed-off-by: Peter Korsgaard <peter@korsgaard.com> |
||
---|---|---|
.. | ||
0001-flxdec-add-some-write-bounds-checking.patch | ||
0002-flxdec-fix-some-warnings-comparing-unsigned-0.patch | ||
0003-flxdec-Don-t-unref-parent-in-the-chain-function.patch | ||
0004-flxdec-rewrite-logic-based-on-GstByteReader-Writer.patch | ||
Config.in | ||
gst1-plugins-good.hash | ||
gst1-plugins-good.mk |