Ubuntu 6611 Published by

Ubuntu Linux has received updates addressing multiple security vulnerabilities, including those related to EditorConfig, Spring Framework, YARA, the Linux kernel, libvpx, PHPUnit, GStreamer Base Plugins, and GStreamer Good Plugins:

[USN-7168-1] EditorConfig vulnerabilities
[USN-7165-1] Spring Framework vulnerability
[USN-7177-1] YARA vulnerability
[USN-7169-2] Linux kernel (GCP) vulnerabilities
[USN-7172-1] libvpx vulnerability
[USN-7171-1] PHPUnit vulnerability
[USN-7175-1] GStreamer Base Plugins vulnerabilities
[USN-7174-1] GStreamer vulnerability
[USN-7176-1] GStreamer Good Plugins vulnerabilities




[USN-7168-1] EditorConfig vulnerabilities


==========================================================================
Ubuntu Security Notice USN-7168-1
December 18, 2024

editorconfig-core vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS

Summary:

EditorConfig could be made to crash or run programs as your login if it
received specially crafted input.

Software Description:
- editorconfig-core: coding style indenter for all editors

Details:

It was discovered that EditorConfig improperly managed memory when handling
certain inputs, leading to overflows. An attacker could possibly use these
issues to cause a denial of service, or execute arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS
editorconfig 0.12.5-2ubuntu0.1~esm2
Available with Ubuntu Pro
libeditorconfig0 0.12.5-2ubuntu0.1~esm2
Available with Ubuntu Pro

Ubuntu 20.04 LTS
editorconfig 0.12.1-1.1+deb11u1build0.20.04.1
libeditorconfig0 0.12.1-1.1+deb11u1build0.20.04.1

Ubuntu 18.04 LTS
editorconfig 0.12.1-1.1ubuntu0.18.04.1~esm2
Available with Ubuntu Pro
libeditorconfig0 0.12.1-1.1ubuntu0.18.04.1~esm2
Available with Ubuntu Pro

Ubuntu 16.04 LTS
editorconfig 0.12.0-2ubuntu0.1~esm2
Available with Ubuntu Pro
libeditorconfig0 0.12.0-2ubuntu0.1~esm2
Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-7168-1
CVE-2023-0341, CVE-2024-53849

Package Information:
https://launchpad.net/ubuntu/+source/editorconfig-core/0.12.1-1.1+deb11u1build0.20.04.1



[USN-7165-1] Spring Framework vulnerability


==========================================================================
Ubuntu Security Notice USN-7165-1
December 17, 2024

libspring-java vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 24.10
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS

Summary:

Spring Framework could be made to run programs or expose sensitive
information if it received specially crafted network traffic.

Software Description:
- libspring-java: Modular Java/J2EE application framework

Details:

It was discovered that the Spring Framework incorrectly handled web
requests via data binding. An attacker could possibly use this issue to
achieve remote code execution and obtain sensitive information.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 24.10
  libspring-aop-java              4.3.30-2ubuntu0.24.10.1
  libspring-beans-java            4.3.30-2ubuntu0.24.10.1
  libspring-context-java          4.3.30-2ubuntu0.24.10.1
  libspring-context-support-java  4.3.30-2ubuntu0.24.10.1
  libspring-core-java             4.3.30-2ubuntu0.24.10.1
  libspring-expression-java       4.3.30-2ubuntu0.24.10.1
  libspring-instrument-java       4.3.30-2ubuntu0.24.10.1
  libspring-jdbc-java             4.3.30-2ubuntu0.24.10.1
  libspring-jms-java              4.3.30-2ubuntu0.24.10.1
  libspring-messaging-java        4.3.30-2ubuntu0.24.10.1
  libspring-orm-java              4.3.30-2ubuntu0.24.10.1
  libspring-oxm-java              4.3.30-2ubuntu0.24.10.1
  libspring-transaction-java      4.3.30-2ubuntu0.24.10.1
  libspring-web-java              4.3.30-2ubuntu0.24.10.1
  libspring-web-portlet-java      4.3.30-2ubuntu0.24.10.1
  libspring-web-servlet-java      4.3.30-2ubuntu0.24.10.1

Ubuntu 24.04 LTS
  libspring-aop-java              4.3.30-2ubuntu0.24.04.1~esm1
                                  Available with Ubuntu Pro
  libspring-beans-java            4.3.30-2ubuntu0.24.04.1~esm1
                                  Available with Ubuntu Pro
  libspring-context-java          4.3.30-2ubuntu0.24.04.1~esm1
                                  Available with Ubuntu Pro
  libspring-context-support-java  4.3.30-2ubuntu0.24.04.1~esm1
                                  Available with Ubuntu Pro
  libspring-core-java             4.3.30-2ubuntu0.24.04.1~esm1
                                  Available with Ubuntu Pro
  libspring-expression-java       4.3.30-2ubuntu0.24.04.1~esm1
                                  Available with Ubuntu Pro
  libspring-instrument-java       4.3.30-2ubuntu0.24.04.1~esm1
                                  Available with Ubuntu Pro
  libspring-jdbc-java             4.3.30-2ubuntu0.24.04.1~esm1
                                  Available with Ubuntu Pro
  libspring-jms-java              4.3.30-2ubuntu0.24.04.1~esm1
                                  Available with Ubuntu Pro
  libspring-messaging-java        4.3.30-2ubuntu0.24.04.1~esm1
                                  Available with Ubuntu Pro
  libspring-orm-java              4.3.30-2ubuntu0.24.04.1~esm1
                                  Available with Ubuntu Pro
  libspring-oxm-java              4.3.30-2ubuntu0.24.04.1~esm1
                                  Available with Ubuntu Pro
  libspring-transaction-java      4.3.30-2ubuntu0.24.04.1~esm1
                                  Available with Ubuntu Pro
  libspring-web-java              4.3.30-2ubuntu0.24.04.1~esm1
                                  Available with Ubuntu Pro
  libspring-web-portlet-java      4.3.30-2ubuntu0.24.04.1~esm1
                                  Available with Ubuntu Pro
  libspring-web-servlet-java      4.3.30-2ubuntu0.24.04.1~esm1
                                  Available with Ubuntu Pro

Ubuntu 22.04 LTS
  libspring-aop-java              4.3.30-1ubuntu0.1~esm1
                                  Available with Ubuntu Pro
  libspring-beans-java            4.3.30-1ubuntu0.1~esm1
                                  Available with Ubuntu Pro
  libspring-context-java          4.3.30-1ubuntu0.1~esm1
                                  Available with Ubuntu Pro
  libspring-context-support-java  4.3.30-1ubuntu0.1~esm1
                                  Available with Ubuntu Pro
  libspring-core-java             4.3.30-1ubuntu0.1~esm1
                                  Available with Ubuntu Pro
  libspring-expression-java       4.3.30-1ubuntu0.1~esm1
                                  Available with Ubuntu Pro
  libspring-instrument-java       4.3.30-1ubuntu0.1~esm1
                                  Available with Ubuntu Pro
  libspring-jdbc-java             4.3.30-1ubuntu0.1~esm1
                                  Available with Ubuntu Pro
  libspring-jms-java              4.3.30-1ubuntu0.1~esm1
                                  Available with Ubuntu Pro
  libspring-messaging-java        4.3.30-1ubuntu0.1~esm1
                                  Available with Ubuntu Pro
  libspring-orm-java              4.3.30-1ubuntu0.1~esm1
                                  Available with Ubuntu Pro
  libspring-oxm-java              4.3.30-1ubuntu0.1~esm1
                                  Available with Ubuntu Pro
  libspring-transaction-java      4.3.30-1ubuntu0.1~esm1
                                  Available with Ubuntu Pro
  libspring-web-java              4.3.30-1ubuntu0.1~esm1
                                  Available with Ubuntu Pro
  libspring-web-portlet-java      4.3.30-1ubuntu0.1~esm1
                                  Available with Ubuntu Pro
  libspring-web-servlet-java      4.3.30-1ubuntu0.1~esm1
                                  Available with Ubuntu Pro

Ubuntu 20.04 LTS
  libspring-aop-java              4.3.22-4ubuntu0.1~esm1
                                  Available with Ubuntu Pro
  libspring-beans-java            4.3.22-4ubuntu0.1~esm1
                                  Available with Ubuntu Pro
  libspring-context-java          4.3.22-4ubuntu0.1~esm1
                                  Available with Ubuntu Pro
  libspring-context-support-java  4.3.22-4ubuntu0.1~esm1
                                  Available with Ubuntu Pro
  libspring-core-java             4.3.22-4ubuntu0.1~esm1
                                  Available with Ubuntu Pro
  libspring-expression-java       4.3.22-4ubuntu0.1~esm1
                                  Available with Ubuntu Pro
  libspring-instrument-java       4.3.22-4ubuntu0.1~esm1
                                  Available with Ubuntu Pro
  libspring-jdbc-java             4.3.22-4ubuntu0.1~esm1
                                  Available with Ubuntu Pro
  libspring-jms-java              4.3.22-4ubuntu0.1~esm1
                                  Available with Ubuntu Pro
  libspring-messaging-java        4.3.22-4ubuntu0.1~esm1
                                  Available with Ubuntu Pro
  libspring-orm-java              4.3.22-4ubuntu0.1~esm1
                                  Available with Ubuntu Pro
  libspring-oxm-java              4.3.22-4ubuntu0.1~esm1
                                  Available with Ubuntu Pro
  libspring-transaction-java      4.3.22-4ubuntu0.1~esm1
                                  Available with Ubuntu Pro
  libspring-web-java              4.3.22-4ubuntu0.1~esm1
                                  Available with Ubuntu Pro
  libspring-web-portlet-java      4.3.22-4ubuntu0.1~esm1
                                  Available with Ubuntu Pro
  libspring-web-servlet-java      4.3.22-4ubuntu0.1~esm1
                                  Available with Ubuntu Pro

Ubuntu 18.04 LTS
  libspring-aop-java              4.3.22-1~18.04.1~esm1
                                  Available with Ubuntu Pro
  libspring-beans-java            4.3.22-1~18.04.1~esm1
                                  Available with Ubuntu Pro
  libspring-context-java          4.3.22-1~18.04.1~esm1
                                  Available with Ubuntu Pro
  libspring-context-support-java  4.3.22-1~18.04.1~esm1
                                  Available with Ubuntu Pro
  libspring-core-java             4.3.22-1~18.04.1~esm1
                                  Available with Ubuntu Pro
  libspring-expression-java       4.3.22-1~18.04.1~esm1
                                  Available with Ubuntu Pro
  libspring-instrument-java       4.3.22-1~18.04.1~esm1
                                  Available with Ubuntu Pro
  libspring-jdbc-java             4.3.22-1~18.04.1~esm1
                                  Available with Ubuntu Pro
  libspring-jms-java              4.3.22-1~18.04.1~esm1
                                  Available with Ubuntu Pro
  libspring-messaging-java        4.3.22-1~18.04.1~esm1
                                  Available with Ubuntu Pro
  libspring-orm-java              4.3.22-1~18.04.1~esm1
                                  Available with Ubuntu Pro
  libspring-oxm-java              4.3.22-1~18.04.1~esm1
                                  Available with Ubuntu Pro
  libspring-transaction-java      4.3.22-1~18.04.1~esm1
                                  Available with Ubuntu Pro
  libspring-web-java              4.3.22-1~18.04.1~esm1
                                  Available with Ubuntu Pro
  libspring-web-portlet-java      4.3.22-1~18.04.1~esm1
                                  Available with Ubuntu Pro
  libspring-web-servlet-java      4.3.22-1~18.04.1~esm1
                                  Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-7165-1
  CVE-2022-22965

Package Information:
https://launchpad.net/ubuntu/+source/libspring-java/4.3.30-2ubuntu0.24.10.1



[USN-7177-1] YARA vulnerability


==========================================================================
Ubuntu Security Notice USN-7177-1
December 18, 2024

yara vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.04 LTS

Summary:

YARA could be made to crash if it received specially crafted
input.

Software Description:
- yara: Pattern matching swiss knife for malware researchers

Details:

It was discovered that YARA did not properly sanitize its
configuration settings. An attacker could potentially exploit this issue to
cause a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS
libyara8 4.1.3-1ubuntu0.1~esm1
Available with Ubuntu Pro
yara 4.1.3-1ubuntu0.1~esm1
Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-7177-1
CVE-2021-45429



[USN-7169-2] Linux kernel (GCP) vulnerabilities


==========================================================================
Ubuntu Security Notice USN-7169-2
December 18, 2024

linux-gcp vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 24.10

Summary:

Several security issues were fixed in the Linux kernel.

Software Description:
- linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems

Details:

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Ext4 file system;
- Network traffic control;
- VMware vSockets driver;
(CVE-2024-49967, CVE-2024-53057, CVE-2024-50264)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 24.10
linux-image-6.11.0-1006-gcp 6.11.0-1006.6
linux-image-gcp 6.11.0-1006.6

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
https://ubuntu.com/security/notices/USN-7169-2
https://ubuntu.com/security/notices/USN-7169-1
CVE-2024-49967, CVE-2024-50264, CVE-2024-53057

Package Information:
https://launchpad.net/ubuntu/+source/linux-gcp/6.11.0-1006.6



[USN-7172-1] libvpx vulnerability


==========================================================================
Ubuntu Security Notice USN-7172-1
December 18, 2024

libvpx vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.04 LTS

Summary:

libvpx could be made to crash or run programs if it received specially
crafted input.

Software Description:
- libvpx: VP8 and VP9 video codec

Details:

It was discovered that libvpx did not properly handle certain malformed
media files. If an application using libvpx opened a specially crafted
file, a remote attacker could cause a denial of service, or possibly
execute arbitrary code. Ubuntu 22.04 LTS, Ubuntu 20.04 LTS, Ubuntu 18.04
LTS, and Ubuntu 16.04 LTS were previously addressed in USN-6403-1,
USN-6403-2, and USN-6403-3. This update addresses the issue in Ubuntu 14.04
LTS.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS
  libvpx1                         1.3.0-2ubuntu0.1~esm3
                                  Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-7172-1
  CVE-2023-5217



[USN-7171-1] PHPUnit vulnerability


==========================================================================
Ubuntu Security Notice USN-7171-1
December 18, 2024

phpunit vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 LTS

Summary:

PHPUnit could be made to crash or run programs if it received specially
crafted network traffic.

Software Description:
- phpunit: Unit testing suite for PHP

Details:

It was discovered that PHPUnit incorrectly handled web requests if exposed
to the internet. An attacker could possibly use this issue to achive remote
code execution or obtain sensitive information.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS
  phpunit                         5.1.3-1+ubuntu3+esm1
                                  Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-7171-1
  CVE-2017-9841



[USN-7175-1] GStreamer Base Plugins vulnerabilities


==========================================================================
Ubuntu Security Notice USN-7175-1
December 18, 2024

gst-plugins-base1.0 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 24.10
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS

Summary:

GStreamer Base Plugins could be made to crash or run programs as your login
if it opened a specially crafted file.

Software Description:
- gst-plugins-base1.0: GStreamer plugins

Details:

Antonio Morales discovered that GStreamer Base Plugins incorrectly handled
certain malformed media files. An attacker could use these issues to cause
GStreamer Base Plugins to crash, resulting in a denial of service, or
possibly execute arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 24.10
gstreamer1.0-alsa 1.24.8-1ubuntu0.1
gstreamer1.0-gl 1.24.8-1ubuntu0.1
gstreamer1.0-plugins-base 1.24.8-1ubuntu0.1
gstreamer1.0-plugins-base-apps 1.24.8-1ubuntu0.1
gstreamer1.0-x 1.24.8-1ubuntu0.1
libgstreamer-gl1.0-0 1.24.8-1ubuntu0.1
libgstreamer-plugins-base1.0-0 1.24.8-1ubuntu0.1

Ubuntu 24.04 LTS
gstreamer1.0-alsa 1.24.2-1ubuntu0.2
gstreamer1.0-gl 1.24.2-1ubuntu0.2
gstreamer1.0-plugins-base 1.24.2-1ubuntu0.2
gstreamer1.0-plugins-base-apps 1.24.2-1ubuntu0.2
gstreamer1.0-x 1.24.2-1ubuntu0.2
libgstreamer-gl1.0-0 1.24.2-1ubuntu0.2
libgstreamer-plugins-base1.0-0 1.24.2-1ubuntu0.2

Ubuntu 22.04 LTS
gstreamer1.0-alsa 1.20.1-1ubuntu0.4
gstreamer1.0-gl 1.20.1-1ubuntu0.4
gstreamer1.0-plugins-base 1.20.1-1ubuntu0.4
gstreamer1.0-plugins-base-apps 1.20.1-1ubuntu0.4
gstreamer1.0-x 1.20.1-1ubuntu0.4
libgstreamer-gl1.0-0 1.20.1-1ubuntu0.4
libgstreamer-plugins-base1.0-0 1.20.1-1ubuntu0.4

Ubuntu 20.04 LTS
gstreamer1.0-alsa 1.16.3-0ubuntu1.4
gstreamer1.0-gl 1.16.3-0ubuntu1.4
gstreamer1.0-plugins-base 1.16.3-0ubuntu1.4
gstreamer1.0-plugins-base-apps 1.16.3-0ubuntu1.4
gstreamer1.0-plugins-base-doc 1.16.3-0ubuntu1.4
gstreamer1.0-x 1.16.3-0ubuntu1.4
libgstreamer-gl1.0-0 1.16.3-0ubuntu1.4
libgstreamer-plugins-base1.0-0 1.16.3-0ubuntu1.4

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-7175-1
CVE-2024-47538, CVE-2024-47541, CVE-2024-47542, CVE-2024-47600,
CVE-2024-47607, CVE-2024-47615, CVE-2024-47835

Package Information:
https://launchpad.net/ubuntu/+source/gst-plugins-base1.0/1.24.8-1ubuntu0.1
https://launchpad.net/ubuntu/+source/gst-plugins-base1.0/1.24.2-1ubuntu0.2
https://launchpad.net/ubuntu/+source/gst-plugins-base1.0/1.20.1-1ubuntu0.4
https://launchpad.net/ubuntu/+source/gst-plugins-base1.0/1.16.3-0ubuntu1.4



[USN-7174-1] GStreamer vulnerability


==========================================================================
Ubuntu Security Notice USN-7174-1
December 18, 2024

gstreamer1.0 vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 24.10
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS

Summary:

GStreamer could be made to crash or run programs as your login if it opened
a specially crafted file.

Software Description:
- gstreamer1.0: GStreamer is a streaming media framework

Details:

Antonio Morales discovered that GStreamer incorrectly handled allocating
memory for certain buffers. An attacker could use this issue to cause
GStreamer to crash, resulting in a denial of service, or possibly execute
arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 24.10
libgstreamer1.0-0 1.24.8-1ubuntu0.1

Ubuntu 24.04 LTS
libgstreamer1.0-0 1.24.2-1ubuntu0.1

Ubuntu 22.04 LTS
libgstreamer1.0-0 1.20.3-0ubuntu1.1

Ubuntu 20.04 LTS
libgstreamer1.0-0 1.16.3-0ubuntu1.2

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-7174-1
CVE-2024-47606

Package Information:
https://launchpad.net/ubuntu/+source/gstreamer1.0/1.24.8-1ubuntu0.1
https://launchpad.net/ubuntu/+source/gstreamer1.0/1.24.2-1ubuntu0.1
https://launchpad.net/ubuntu/+source/gstreamer1.0/1.20.3-0ubuntu1.1
https://launchpad.net/ubuntu/+source/gstreamer1.0/1.16.3-0ubuntu1.2



[USN-7176-1] GStreamer Good Plugins vulnerabilities


==========================================================================
Ubuntu Security Notice USN-7176-1
December 18, 2024

gst-plugins-good1.0 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 24.10
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS

Summary:

GStreamer Good Plugins could be made to crash or run programs as your login
if it opened a specially crafted file.

Software Description:
- gst-plugins-good1.0: GStreamer plugins

Details:

Antonio Morales discovered that GStreamer Good Plugins incorrectly handled
certain malformed media files. An attacker could use these issues to cause
GStreamer Good Plugins to crash, resulting in a denial of service, or
possibly execute arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 24.10
gstreamer1.0-gtk3 1.24.8-1ubuntu1.1
gstreamer1.0-plugins-good 1.24.8-1ubuntu1.1
gstreamer1.0-pulseaudio 1.24.8-1ubuntu1.1
gstreamer1.0-qt5 1.24.8-1ubuntu1.1
gstreamer1.0-qt6 1.24.8-1ubuntu1.1
libgstreamer-plugins-good1.0-0 1.24.8-1ubuntu1.1

Ubuntu 24.04 LTS
gstreamer1.0-gtk3 1.24.2-1ubuntu1.1
gstreamer1.0-plugins-good 1.24.2-1ubuntu1.1
gstreamer1.0-pulseaudio 1.24.2-1ubuntu1.1
gstreamer1.0-qt5 1.24.2-1ubuntu1.1
gstreamer1.0-qt6 1.24.2-1ubuntu1.1
libgstreamer-plugins-good1.0-0 1.24.2-1ubuntu1.1

Ubuntu 22.04 LTS
gstreamer1.0-gtk3 1.20.3-0ubuntu1.3
gstreamer1.0-plugins-good 1.20.3-0ubuntu1.3
gstreamer1.0-pulseaudio 1.20.3-0ubuntu1.3
gstreamer1.0-qt5 1.20.3-0ubuntu1.3
libgstreamer-plugins-good1.0-0 1.20.3-0ubuntu1.3

Ubuntu 20.04 LTS
gstreamer1.0-gtk3 1.16.3-0ubuntu1.3
gstreamer1.0-plugins-good 1.16.3-0ubuntu1.3
gstreamer1.0-pulseaudio 1.16.3-0ubuntu1.3
gstreamer1.0-qt5 1.16.3-0ubuntu1.3
libgstreamer-plugins-good1.0-0 1.16.3-0ubuntu1.3

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-7176-1
CVE-2024-47537, CVE-2024-47539, CVE-2024-47540, CVE-2024-47543,
CVE-2024-47544, CVE-2024-47545, CVE-2024-47546, CVE-2024-47596,
CVE-2024-47597, CVE-2024-47598, CVE-2024-47599, CVE-2024-47601,
CVE-2024-47602, CVE-2024-47603, CVE-2024-47606, CVE-2024-47613,
CVE-2024-47774, CVE-2024-47775, CVE-2024-47776, CVE-2024-47777,
CVE-2024-47778, CVE-2024-47834

Package Information:
https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.24.8-1ubuntu1.1
https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.24.2-1ubuntu1.1
https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.20.3-0ubuntu1.3
https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.16.3-0ubuntu1.3