Opened 15 months ago
Closed 15 months ago
#18853 closed enhancement (fixed)
gstreamer-1.22.7 gst-plugins-base gst-plugins-good gst-plugins-bad gst-plugins-ugly gst-libav gstreamer-vaapi
Reported by: | Bruce Dubbs | Owned by: | Douglas R. Reno |
---|---|---|---|
Priority: | elevated | Milestone: | 12.1 |
Component: | BOOK | Version: | git |
Severity: | normal | Keywords: | |
Cc: |
Description
New point version.
Change History (5)
comment:1 by , 15 months ago
Priority: | normal → elevated |
---|
comment:2 by , 15 months ago
I've encountered a test failure with several gst-plugins-bad releases: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/issues/3124
This is related to something in my $HOME (setting HOME=
make this test case pass) so maybe you cannot reproduce it.
comment:3 by , 15 months ago
Owner: | changed from | to
---|---|
Status: | new → assigned |
comment:4 by , 15 months ago
CVE-2023-44446
Security Advisory 2023-0010 (ZDI-CAN-22299) (CVE-2023-44446)
Summary MXF demuxer use-after-free
Date 2023-11-13 12:00
Affected Versions GStreamer gst-plugins-bad < 1.22.7
ID GStreamer-SA-2023-0010
ZDI-CAN-22299
CVE-2023-44446
Details
Use-after-free (read) in the MXF demuxer when handling certain files before GStreamer 1.22.7
Impact
It is possible for a malicious third party to trigger a crash in the application.
CVE-2023-44429
Security Advisory 2023-0009 (ZDI-CAN-22226) (CVE-2023-44429)
Summary AV1 codec parser buffer overflow
Date 2023-11-13 12:00
Affected Versions GStreamer gst-plugins-bad < 1.22.7
ID GStreamer-SA-2023-0009
ZDI-CAN-22226
CVE-2023-44429
Details
Heap-based buffer overflow in the AV1 codec parser when handling certain malformed streams before GStreamer 1.22.7
Impact
It is possible for a malicious third party to trigger a crash in the application, and possibly also effect code execution through heap manipulation.
comment:5 by , 15 months ago
Resolution: | → fixed |
---|---|
Status: | assigned → closed |
Fixed at a1fe0cf75bc447df68869baf4c270c5c2eac0422
SA-12.0-042 issued
Highlighted bugfixes:
See the GStreamer 1.22.7 release notes for more details.