Opened 2 years ago
Closed 2 years ago
#19184 closed enhancement (fixed)
gstreamer-1.22.9 gst-plugins-base gst-plugins-good gst-plugins-bad gst-plugins-ugly gst-libav gstreamer-vaapi
| Reported by: | Bruce Dubbs | Owned by: | Douglas R. Reno |
|---|---|---|---|
| Priority: | elevated | Milestone: | 12.1 |
| Component: | BOOK | Version: | git |
| Severity: | normal | Keywords: | |
| Cc: |
Description
New point version.
Change History (5)
comment:1 by , 2 years ago
comment:2 by , 2 years ago
| Priority: | normal → elevated |
|---|
comment:3 by , 2 years ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:4 by , 2 years ago
Summary: AV1 codec parser potential buffer overflow during tile list parsing
Details: Heap-based buffer overflow in the AV1 codec parser when handling certain malformed streams before GStreamer 1.22.9
Impact: It is possible for a malicious third party to trigger a crash in the application, and possibly also effect code execution through heap manipulation.
The CVE number is CVE-2024-0444
comment:5 by , 2 years ago
| Resolution: | → fixed |
|---|---|
| Status: | assigned → closed |
Fixed at 5d82b9253580dd8864a6bba9742b935c00b37c92
SA-12.0-081 issued
Note:
See TracTickets
for help on using tickets.

Highlighted bugfixes in 1.22.9
gstreamer
gst-plugins-base
gst-plugins-good
gst-plugins-bad
gst-plugins-ugly
gst-libav
gstreamer-vaapi