安全公告详情

NS-SA-2026-0052

2026-07-27 21:21:29

简介

important: gstreamer1-plugins-good/harfbuzz security update

严重级别

important

主题

An update for gstreamer1-plugins-good/harfbuzz is now available for NewStart CGSL MAIN 6.06.
NewStart Security has rated this update as having a security impact of important. A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.

详细描述

gstreamer1-plugins-good:
harfbuzz:


Security Fix(es):
gstreamer1-plugins-good: A flaw was found in the MP4/MOV demuxer and memory allocator in the GStreamer library. Processing a specially crafted input file can cause an integer overflow in the qtdemux_parse_theora_extension function. This issue leads to a small amount of memory being allocated to store a large input size, resulting in an out-of-bounds write.(CVE-2024-47606)
gstreamer1-plugins-good: bugfix
harfbuzz: A vulnerability was found HarfBuzz. This flaw allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.(CVE-2023-25193)
harfbuzz: bugfix


Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
http://security.gd-linux.com/how_to_apply_patch.html
Remember the build tag is 6.06.11B10.

影响组件

  • gstreamer1-plugins-good
  • harfbuzz

影响产品

  • CGSL MAIN 6.06

更新包

{"fix":[{"product":"CGSL MAIN 6.06","pkgs":[{"binary":["gstreamer1-plugins-good-1.16.1-5.zncgsl6.x86_64.rpm"],"source":"gstreamer1-plugins-good-1.16.1-5.zncgsl6.src.rpm"},{"binary":["harfbuzz-2.7.4-10.0.1.zncgsl6.x86_64.rpm","harfbuzz-devel-2.7.4-10.0.1.zncgsl6.x86_64.rpm","harfbuzz-icu-2.7.4-10.0.1.zncgsl6.x86_64.rpm"],"source":"harfbuzz-2.7.4-10.0.1.zncgsl6.src.rpm"}]}]}

CVE

参考