Opened 13 months ago
Closed 13 months ago
#19184 closed enhancement (fixed)
gstreamer-1.22.9 gst-plugins-base gst-plugins-good gst-plugins-bad gst-plugins-ugly gst-libav gstreamer-vaapi
Reported by: | Bruce Dubbs | Owned by: | Douglas R. Reno |
---|---|---|---|
Priority: | elevated | Milestone: | 12.1 |
Component: | BOOK | Version: | git |
Severity: | normal | Keywords: | |
Cc: |
Description
New point version.
Change History (5)
comment:1 by , 13 months ago
comment:2 by , 13 months ago
Priority: | normal → elevated |
---|
comment:3 by , 13 months ago
Owner: | changed from | to
---|---|
Status: | new → assigned |
comment:4 by , 13 months ago
Summary: AV1 codec parser potential buffer overflow during tile list parsing
Details: Heap-based buffer overflow in the AV1 codec parser when handling certain malformed streams before GStreamer 1.22.9
Impact: It is possible for a malicious third party to trigger a crash in the application, and possibly also effect code execution through heap manipulation.
The CVE number is CVE-2024-0444
comment:5 by , 13 months ago
Resolution: | → fixed |
---|---|
Status: | assigned → closed |
Fixed at 5d82b9253580dd8864a6bba9742b935c00b37c92
SA-12.0-081 issued
Note:
See TracTickets
for help on using tickets.
Highlighted bugfixes in 1.22.9
gstreamer
gst-plugins-base
gst-plugins-good
gst-plugins-bad
gst-plugins-ugly
gst-libav
gstreamer-vaapi