Chapter 1. Package Updates
84
This update has been rated as having important security impact by the Red Hat Security Response
Team.
GStreamer is a streaming media framework, based on graphs of filters which operate on media
data. GStreamer Good Plug-ins is a collection of well-supported, GStreamer plug-ins of good quality
released under the LGPL license.
Multiple heap buffer overflows and an array indexing error were found in the GStreamer's QuickTime
media file format decoding plugin. An attacker could create a carefully-crafted QuickTime media .mov
file that would cause an application using GStreamer to crash or, potentially, execute arbitrary code if
played by a victim. (
CVE-2009-0386
502
,
CVE-2009-0387
503
,
CVE-2009-0397
504
)
All users of gstreamer-plugins-good are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the update, all applications using
GStreamer (such as totem or rhythmbox) must be restarted for the changes to take effect.
1.78. gtk-vnc
1.78.1. RHBA-2009:1301: bug fix update
An updated gtk-vnc package that fixes several bugs is now available.
gtk-vnc is a VNC viewer widget for GTK. It is built using co-routines allowing it to be completely
asynchronous while remaining single threaded.
This update addresses the following issues:
• the handling of the virtual mouse pointer could result in the pointer getting stuck against an invisible
wall, unable to move into some areas of the virtual machine display area. (
BZ#487560
505
)
• handling of non-US layout keyboards had flaws making it impossible to type certain key sequences,
for example Shift+Tab. (
BZ#357491
506
)
• the gtk-vnc package was re-based to version 0.3.8, from version 0.3.2, to address problems
with virtual mouse pointer movement handling and the conversion of "keysyms" for non-US
layout keyboards. The update also improves interoperability with VNC servers and extensions.
(
BZ#489326
507
)
All gtk-vnc users should install this updated package which addresses these issues.
1.79. hal
1.79.1. RHBA-2009:1359: bug fix and enhancement update
An updated hal package that fixes various bugs and adds several enhancements is now available.
HAL is daemon for collection and maintaining information from several sources about the hardware on
the system. It provides a live device list through D-BUS.
502
https://www.redhat.com/security/data/cve/CVE-2009-0386.html
503
https://www.redhat.com/security/data/cve/CVE-2009-0387.html
504
https://www.redhat.com/security/data/cve/CVE-2009-0397.html
Содержание ENTERPRISE 5.4 RELEASE NOTES
Страница 1: ...Red Hat Enterprise Linux 5 4 Technical Notes Every Change to Every Package ...
Страница 18: ...xviii ...
Страница 306: ...288 ...
Страница 464: ...446 ...
Страница 466: ...448 ...