#18318 closed enhancement (fixed)
gstreamer gst-plugins-base gst-plugins-good gst-plugins-bad gst-plugins-ugly gst-libav gstreamer-vaapi 1.22.5
Reported by: | Douglas R. Reno | Owned by: | Douglas R. Reno |
---|---|---|---|
Priority: | elevated | Milestone: | 12.0 |
Component: | BOOK | Version: | git |
Severity: | normal | Keywords: | |
Cc: |
Description ¶
New point version, contains some security fixes in it.
Change History (5)
comment:2 by , 21 months ago
Security Vulnerability #1:
Security Advisory 2023-0005 (ZDI-CAN-21444) Summary Integer overflow leading to heap overwrite in RealMedia file handling Date 2023-07-20 14:00 Affected Versions GStreamer gst-plugins-ugly 1.x < 1.22.5, 0.10.x ID GStreamer-SA-2023-0005 ZDI-CAN-21444 Details Heap-based buffer overflow in the RealMedia file demuxer when handling malformed files in GStreamer versions before 1.22.5. Impact It is possible for a malicious third party to trigger a crash in the application, and possibly also effect code execution through heap manipulation.
No CVE assigned yet, it'll take a while for that, so we'll refer to these by their ZDIs. The vulnerabilities from the last set have CVEs now though.
Security Vulnerability #2:
Security Advisory 2023-0004 (ZDI-CAN-21443) Summary Integer overflow leading to heap overwrite in RealMedia file handling Date 2023-07-20 14:00 Affected Versions GStreamer gst-plugins-ugly 1.x < 1.22.5, 0.10.x ID GStreamer-SA-2023-0004 ZDI-CAN-21443 Details Heap-based buffer overflow in the RealMedia file demuxer when handling malformed files in GStreamer versions before 1.22.5. Impact It is possible for a malicious third party to trigger a crash in the application, and possibly also effect code execution through heap manipulation.
comment:3 by , 21 months ago
Owner: | changed from | to
---|---|
Status: | new → assigned |
comment:4 by , 21 months ago
Resolution: | → fixed |
---|---|
Status: | assigned → closed |
Fixed at 4d5febb6be8e8248194fe6a4188e74c0ab073804
SA-11.3-064 issued
Note:
See TracTickets
for help on using tickets.