Scientific Linux Security Update : gstreamer-plugins on SL4.x i386/x86_64
Medium Nessus Plugin ID 61030
SynopsisThe remote Scientific Linux host is missing one or more security updates.
DescriptionAn integer overflow flaw, leading to a heap-based buffer overflow, and a stack-based buffer overflow flaw were found in various ModPlug music file format library (libmodplug) modules, embedded in GStreamer. An attacker could create specially crafted music files that, when played by a victim, would cause applications using GStreamer to crash or, potentially, execute arbitrary code. (CVE-2006-4192, CVE-2011-1574)
All applications using GStreamer (such as Rhythmbox) must be restarted for the changes to take effect.
SolutionUpdate the affected gstreamer-plugins and / or gstreamer-plugins-devel packages.