安全公告详情

NS-SA-2026-0103

2026-09-07 18:00:00

简介

important: gstreamer1-plugins-good/ply security update

严重级别

important

主题

An update for gstreamer1-plugins-good/ply is now available for NewStart CGSL MAIN 7.02.
NewStart Security has rated this update as having a security impact of important. A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.

详细描述

gstreamer1-plugins-good:
ply:


Security Fix(es):
gstreamer1-plugins-good: A flaw was found in GStreamer. This out-of-bounds write vulnerability in the DVB (Digital Video Broadcasting) Subtitles handling allows remote attackers to execute arbitrary code. The issue stems from improper validation of user-supplied coordinate data, which can lead to writing beyond the boundaries of an allocated memory buffer. Successful exploitation can result in arbitrary code execution within the context of the current process.(CVE-2026-2923)
gstreamer1-plugins-good: A flaw was found in gstreamer1-plugins-good. The isomp4 plugin's qtdemux_parse_tree function incorrectly handles MP4 file parsing, resulting in a heap buffer over-read. This flaw allows a local attacker to trigger this vulnerability by providing a specially crafted MP4 file. This over-read can lead to information disclosure.(CVE-2025-47183)
gstreamer1-plugins-good: A flaw was found in gstreamer1-plugins-good. The isomp4 plugin's qtdemux_parse_trak function incorrectly handles MP4 file parsing, resulting in a heap buffer over-read. This flaw allows a local attacker to provide a specially crafted MP4 file. This over-read can lead to information disclosure.(CVE-2025-47219)
gstreamer1-plugins-good: bugfix
ply: An arbitrary code execution vulnerability was discovered in PLY (Python Lex-Yacc). When an application uses PLY's undocumented picklefile parameter to load cached parser data, the library deserializes the pickle file without validation. If an attacker can supply or modify the pickle file being loaded, they can embed malicious code that executes automatically during the deserialization process, potentially allowing them to run arbitrary commands on the affected system.(CVE-2025-56005)
ply: bugfix


Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
http://security.gd-linux.com/how_to_apply_patch.html
Remember the build tag is 7.02.07B5.

影响组件

  • gstreamer1-plugins-good
  • ply

影响产品

  • CGSL MAIN 7.02

更新包

{"fix":[{"product":"CGSL MAIN 7.02","pkgs":[{"binary":["gstreamer1-plugins-good-gtk-1.28.1-1.zncgsl7.x86_64.rpm","gstreamer1-plugins-good-qt-1.28.1-1.zncgsl7.x86_64.rpm","gstreamer1-plugins-good-1.28.1-1.zncgsl7.x86_64.rpm"],"source":"gstreamer1-plugins-good-1.28.1-1.zncgsl7.src.rpm"},{"binary":"","source":""}]}]}

CVE

参考