Referenced CVEs:
CVE-2009-1932
Description:
===========================================================Ubuntu Security Notice USN-789-1 June 22, 2009gst-plugins-good0.10 vulnerabilityCVE-2009-1932===========================================================A security issue affects the following Ubuntu releases:Ubuntu 6.06 LTSUbuntu 8.04 LTSUbuntu 8.10Ubuntu 9.04This advisory also applies to the corresponding versions ofKubuntu, Edubuntu, and Xubuntu.The problem can be corrected by upgrading your system to thefollowing package versions:Ubuntu 6.06 LTS: gstreamer0.10-plugins-good 0.10.3-0ubuntu4.2Ubuntu 8.04 LTS: gstreamer0.10-plugins-good 0.10.7-3ubuntu0.3Ubuntu 8.10: gstreamer0.10-plugins-good 0.10.10.4-1ubuntu1.2Ubuntu 9.04: gstreamer0.10-plugins-good 0.10.14-1ubuntu0.1In general, a standard system upgrade is sufficient to effect thenecessary changes.Details follow:Tielei Wang discovered that GStreamer Good Plugins did not correctly handlemalformed PNG image files. If a user were tricked into opening a craftedPNG image file with a GStreamer application, an attacker could cause adenial of service via application crash, or possibly execute arbitrary codewith the privileges of the user invoking the program.
More...