#18190 closed enhancement (fixed)
gstreamer-1.22.4 gst-plugins-base gst-plugins-good gst-plugins-bad gst-plugins-ugly gst-libav gstreamer-vaapi
Reported by: | Bruce Dubbs | Owned by: | Douglas R. Reno |
---|---|---|---|
Priority: | elevated | Milestone: | 12.0 |
Component: | BOOK | Version: | git |
Severity: | normal | Keywords: | |
Cc: |
Description ¶
New point version.
Change History (7)
comment:1 by , 22 months ago
comment:3 by , 22 months ago
Owner: | changed from | to
---|---|
Status: | new → assigned |
comment:4 by , 21 months ago
Security Advisory #1:
Security Advisory 2023-0002 (ZDI-CAN-20968) Summary Heap overwrite in subtitle parsing Date 2023-06-20 18:00 Affected Versions GStreamer gst-plugins-base 1.x < 1.22.4, 0.10.x ID GStreamer-SA-2023-0002 ZDI-CAN-20968 Details Heap-based buffer overflow in the subparse subtitle parser when handling certain SRT subtitle files in GStreamer versions before 1.22.4. Impact It is possible for a malicious third party to trigger a crash in the application, and possibly also effect code execution through heap manipulation.
Security Advisory #2:
Security Advisory 2023-0001 (ZDI-CAN-20775) Summary Integer overflow leading to heap overwrite in FLAC image tag handling Date 2023-06-20 18:00 Affected Versions GStreamer gst-plugins-good 1.x < 1.22.4, 0.10.x ID GStreamer-SA-2023-0001 ZDI-CAN-20775 Details Heap-based buffer overflow in the FLAC parser when handling malformed image tags in GStreamer versions before 1.22.4. Impact It is possible for a malicious third party to trigger a crash in the application, and possibly also effect code execution through heap manipulation.
Security Advisory #3:
Security Advisory 2023-0003 (ZDI-CAN-20994) Summary Heap overwrite in PGS subtitle overlay decoder Date 2023-06-20 18:00 Affected Versions GStreamer gst-plugins-good 1.x < 1.22.4, 0.10.x ID GStreamer-SA-2023-0003 ZDI-CAN-20994 Details Heap-based buffer overflow in the PGS blu-ray subtitle decoder when handling certain files in GStreamer versions before 1.22.4. Impact It is possible for a malicious third party to trigger a crash in the application, and possibly also effect code execution through heap manipulation.
comment:5 by , 21 months ago
Resolution: | → fixed |
---|---|
Status: | assigned → closed |
Note:
See TracTickets
for help on using tickets.
1.22.4
The fourth 1.22 bug-fix release (1.22.4) was released on 20 June 2023.
This release only contains bugfixes and security fixes and it should be safe to update from 1.22.x.
Highlighted bugfixes in 1.22.4
gstreamer
gst-plugins-base
gst-plugins-good
gst-plugins-bad
gst-plugins-ugly
gst-libav
gst-rtsp-server
gstreamer-vaapi