You are here
Home > Preporuke > Sigurnosni nedostaci programskog paketa MediaInfo

Sigurnosni nedostaci programskog paketa MediaInfo

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LUB

=======================================================================
===
Ubuntu Security Notice USN-3988-1
May 16, 2019

libmediainfo vulnerabilities
=======================================================================
===

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 19.04
– Ubuntu 18.10
– Ubuntu 18.04 LTS

Summary:

MediaInfo could be made to crash if it opened a specially crafted file.

Software Description:
– libmediainfo: library reading metadata from media files

Details:

It was discovered that MediaInfo contained multiple security issues
when
handling certain multimedia files. If a user were tricked into opening
a
crafted multimedia file, an attacker could cause MediaInfo to crash,
resulting
in a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 19.04:
libmediainfo0v5 18.12-1ubuntu0.1

Ubuntu 18.10:
libmediainfo0v5 18.03.1-1ubuntu0.1

Ubuntu 18.04 LTS:
libmediainfo0v5 17.12-1ubuntu0.1

In general, a standard system update will make all the necessary
changes.

References:
https://usn.ubuntu.com/usn/usn-3988-1
CVE-2019-11372, CVE-2019-11373

Package Information:
https://launchpad.net/ubuntu/+source/libmediainfo/18.12-1ubuntu0.1
https://launchpad.net/ubuntu/+source/libmediainfo/18.03.1-1ubuntu0.1
https://launchpad.net/ubuntu/+source/libmediainfo/17.12-1ubuntu0.1
—–BEGIN PGP SIGNATURE—–

iQIzBAABCgAdFiEECtyyz6azUy6AZBzSkGeI6zGnN/8FAlzduBoACgkQkGeI6zGn
N//eTQ/+LDY+LSWG8G90bs+srs/Z0zNpjE8LxKFeT/kFN/3NjmNY+OWfG749/u6V
ogXShY2YhHUw811hF/tbXP3ZiTQNNjZPqdlgDp9n9wcNJxfKABRZa3uWAt2v73eS
FKIVWEekUt2JE75/kdZN2suP4s8qwVBC3wznhOKM6tRjY91o0oleLmQziS/sqf6h
i6jH3uOMgy92aJI1YVDhIh2QQZ0oZSjQjZv2OFjiMSddoIXP4qdoCdKWjlKcANuR
PnzH6GUxijI6GVPmkuUPDiNGbfi4po11lF2R5flD4GYL3jv31y6TWqqGbT1LpGa5
4myorj7IklAqDX0f09zhCmzQVwUBWLkILo715+K6IHey7VupyoZ7N2kP3E5mahJH
iBRcXzR+V3gTHDKqTwZD3lRPU37+MHP9jIrZ3gjOtLKoqSs3vHgVi8SMe3uW5t2T
YuufKF+sPJhtLV6y9i5w1ulApm9MZ3OpbWKS/faIEgnflB8x1kRbrW4Fu5TrYfYG
b01rTglUrr3nPkXoMwwC/fL34ypVhM/14VZ+cQfV8cexzIdEigXDbd0ipGD5WGor
EScETdwrxOx9vTCdJvhV1nMsWR3E3+ydqjmti9sV5fKCL/oHpYXvy0w8NKzZWy4E
aFflKaecjINzWl6cZigD4scgDyKGcw6IP3PrxRPeIl/bwwfliqQ=
=9t0B
—–END PGP SIGNATURE—–

AutorZvonimir Bosnjak
Cert idNCERT-REF-2019-05-0001-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
IzvorAdobe
Top
More in Preporuke
Sigurnosni nedostaci programskog paketa Wireshark

Otkriveni su sigurnosni nedostaci u programskom paketu Wireshark za operacijski sustav Ubuntu. Otkriveni nedostaci potencijalnim napadačima omogućuju izazivanje DoS stanja....

Close