Debian Package Tracker
Register | Log in
Subscribe

gst-plugins-ugly1.0

GStreamer plugins from the "ugly" set

Choose email to subscribe with

general
  • source: gst-plugins-ugly1.0 (main)
  • version: 1.28.6-1
  • maintainer: Maintainers of GStreamer packages (DMD)
  • uploaders: Sebastian Dröge [DMD] – Marc Leeman [DMD]
  • arch: any
  • std-ver: 4.7.3
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.18.4-2+deb11u1
  • o-o-sec: 1.18.4-2+deb11u2
  • oldstable: 1.22.0-2+deb12u2
  • old-sec: 1.22.0-2+deb12u2
  • stable: 1.26.3-4+deb13u1
  • stable-sec: 1.26.3-4+deb13u1
  • testing: 1.28.6-1
  • unstable: 1.28.6-1
  • exp: 1.29.2-1
versioned links
  • 1.18.4-2+deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.18.4-2+deb11u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.22.0-2+deb12u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.26.3-4+deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.28.6-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.29.2-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • gstreamer1.0-plugins-ugly
action needed
The VCS repository is not up to date, push the missing commits. high
vcswatch reports that the current version of the package is not in its VCS.
Either you need to push your commits and/or your tags, or the information about the package's VCS are out of date. A common cause of the latter issue when using the Git VCS is not specifying the correct branch when the packaging is not in the default one (remote HEAD branch), which is usually "master" but can be modified in salsa.debian.org in the project's general settings with the "Default Branch" field). Alternatively the Vcs-Git field in debian/control can contain a "-b <branch-name>" suffix to indicate what branch is used for the Debian packaging.

https://salsa.debian.org/api/v4/projects/gstreamer-team%2Fgst-plugins-ugly1.0 API request failed: 401 Unauthorized at /srv/qa.debian.org/data/vcswatch/vcswatch line 410.
Created: 2026-03-23 Last update: 2026-09-08 10:33
3 security issues in bullseye high

There are 3 open security issues in bullseye.

1 important issue:
  • CVE-2026-19389: Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled length and size values can bypass bounds checks and cause out-of-bounds heap reads. This can result in application crash, denial of service, or limited information disclosure when untrusted media is processed.
2 issues postponed or untriaged:
  • CVE-2026-53703: (postponed; to be fixed through a stable update) A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file, the demuxer parses MDPR (media properties) chunks to configure audio streams. For audio stream header versions 4 and 5, the parser reads fields such as codec type, packet size, sample rate, channel count, and extra codec data length from fixed offsets within the chunk without first checking that the chunk contains enough data. If a malicious file provides an MDPR chunk that is too small to contain a complete audio stream header, the parser reads beyond the end of the buffer. This can cause the application to crash. In some cases, bytes read past the buffer boundary may be incorporated into stream metadata, which could result in limited information disclosure.
  • CVE-2026-53704: (postponed; to be fixed through a stable update) A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a RealMedia file containing a specially crafted FILEINFO metadata section, the demuxer parses variable-name and variable-value pairs using re_skip_pascal_string() without validating that offsets remain within the mapped buffer. Additionally, the element count controlling the parsing loop is read from attacker-controlled data without validation, which can cause an infinite loop. A crafted RealMedia file can cause the application to crash, hang, or potentially read limited adjacent memory contents.
Created: 2026-08-10 Last update: 2026-08-11 05:00
3 low-priority security issues in trixie low

There are 3 open security issues in trixie.

3 issues left for the package maintainer to handle:
  • CVE-2026-19389: (needs triaging) Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled length and size values can bypass bounds checks and cause out-of-bounds heap reads. This can result in application crash, denial of service, or limited information disclosure when untrusted media is processed.
  • CVE-2026-53703: (needs triaging) A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file, the demuxer parses MDPR (media properties) chunks to configure audio streams. For audio stream header versions 4 and 5, the parser reads fields such as codec type, packet size, sample rate, channel count, and extra codec data length from fixed offsets within the chunk without first checking that the chunk contains enough data. If a malicious file provides an MDPR chunk that is too small to contain a complete audio stream header, the parser reads beyond the end of the buffer. This can cause the application to crash. In some cases, bytes read past the buffer boundary may be incorporated into stream metadata, which could result in limited information disclosure.
  • CVE-2026-53704: (needs triaging) A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a RealMedia file containing a specially crafted FILEINFO metadata section, the demuxer parses variable-name and variable-value pairs using re_skip_pascal_string() without validating that offsets remain within the mapped buffer. Additionally, the element count controlling the parsing loop is read from attacker-controlled data without validation, which can cause an infinite loop. A crafted RealMedia file can cause the application to crash, hang, or potentially read limited adjacent memory contents.

You can find information about how to handle these issues in the security team's documentation.

Created: 2026-06-16 Last update: 2026-09-08 18:30
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.7.3).
Created: 2026-03-31 Last update: 2026-08-05 22:30
testing migrations
  • excuses:
    • Migration status for gst-plugins-ugly1.0 (1.28.6-1 to 1.28.7-1): Waiting for test results or another package, or too young (no action required now - check later)
    • Issues preventing migration:
    • ∙ ∙ Autopkgtest for mopidy/3.4.2-8: amd64: Pass, arm64: Pass, armhf: Pass, i386: Test triggered, ppc64el: Pass, riscv64: Pass
    • ∙ ∙ Too young, only 2 of 5 days old
    • Additional info (not blocking):
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/g/gst-plugins-ugly1.0.html
    • ∙ ∙ Reproduced on amd64 - info
    • ∙ ∙ Reproduced on arm64 - info
    • ∙ ∙ Reproduced on armhf - info
    • ∙ ∙ Reproduced on i386 - info
    • Not considered
news
[rss feed]
  • [2026-09-08] Accepted gst-plugins-ugly1.0 1.28.7-1 (source) into unstable (Marc Leeman)
  • [2026-08-11] gst-plugins-ugly1.0 1.28.6-1 MIGRATED to testing (Debian testing watch)
  • [2026-08-05] Accepted gst-plugins-ugly1.0 1.28.6-1 (source) into unstable (Marc Leeman)
  • [2026-07-28] Accepted gst-plugins-ugly1.0 1.29.2-1 (source) into experimental (Marc Leeman)
  • [2026-07-22] gst-plugins-ugly1.0 1.28.5-1 MIGRATED to testing (Debian testing watch)
  • [2026-07-16] Accepted gst-plugins-ugly1.0 1.28.5-1 (source) into unstable (Marc Leeman)
  • [2026-06-20] gst-plugins-ugly1.0 1.28.4-1 MIGRATED to testing (Debian testing watch)
  • [2026-06-15] Accepted gst-plugins-ugly1.0 1.28.4-1 (source) into unstable (Marc Leeman)
  • [2026-05-16] gst-plugins-ugly1.0 1.28.3-1 MIGRATED to testing (Debian testing watch)
  • [2026-05-12] Accepted gst-plugins-ugly1.0 1.28.3-1 (source) into unstable (Marc Leeman)
  • [2026-04-13] gst-plugins-ugly1.0 1.28.2-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-08] Accepted gst-plugins-ugly1.0 1.28.2-1 (source) into unstable (Marc Leeman)
  • [2026-04-02] Accepted gst-plugins-ugly1.0 1.26.3-4+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Moritz Mühlenhoff)
  • [2026-04-02] Accepted gst-plugins-ugly1.0 1.22.0-2+deb12u2 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Moritz Mühlenhoff)
  • [2026-04-01] Accepted gst-plugins-ugly1.0 1.22.0-2+deb12u2 (source) into oldstable-security (Debian FTP Masters) (signed by: Moritz Mühlenhoff)
  • [2026-04-01] Accepted gst-plugins-ugly1.0 1.26.3-4+deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Moritz Mühlenhoff)
  • [2026-03-29] Accepted gst-plugins-ugly1.0 1.18.4-2+deb11u2 (source) into oldoldstable-security (Utkarsh Gupta)
  • [2026-03-23] Accepted gst-plugins-ugly1.0 1.29.1-1 (source) into experimental (Marc Leeman)
  • [2026-03-03] gst-plugins-ugly1.0 1.28.1-1 MIGRATED to testing (Debian testing watch)
  • [2026-02-26] Accepted gst-plugins-ugly1.0 1.28.1-1 (source) into unstable (Marc Leeman)
  • [2026-02-03] gst-plugins-ugly1.0 1.28.0-1 MIGRATED to testing (Debian testing watch)
  • [2026-01-28] Accepted gst-plugins-ugly1.0 1.28.0-1 (source) into unstable (Marc Leeman)
  • [2026-01-07] Accepted gst-plugins-ugly1.0 1.27.90-1 (source) into experimental (Marc Leeman)
  • [2026-01-01] gst-plugins-ugly1.0 1.26.10-1 MIGRATED to testing (Debian testing watch)
  • [2025-12-26] Accepted gst-plugins-ugly1.0 1.26.10-1 (source) into unstable (Marc Leeman)
  • [2025-12-11] Accepted gst-plugins-ugly1.0 1.27.50-2 (source) into experimental (Marc Leeman)
  • [2025-12-11] Accepted gst-plugins-ugly1.0 1.27.50-1 (source) into experimental (Marc Leeman)
  • [2025-12-07] gst-plugins-ugly1.0 1.26.9-1 MIGRATED to testing (Debian testing watch)
  • [2025-12-02] Accepted gst-plugins-ugly1.0 1.26.9-1 (source) into unstable (Marc Leeman)
  • [2025-11-18] gst-plugins-ugly1.0 1.26.8-1 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian
  • buildd: logs, exp, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • l10n (-, 89)
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1.28.6-1
  • 1 bug

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing