#19737 closed enhancement (fixed)
gstreamer-1.24.3 gst-plugins-base gst-plugins-good gst-plugins-bad gst-plugins-ugly gst-libav gstreamer-vaapi
| Reported by: | Bruce Dubbs | Owned by: | Bruce Dubbs |
|---|---|---|---|
| Priority: | elevated | Milestone: | 12.2 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New point version.
Change History (5)
comment:1 by , 2 years ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:2 by , 2 years ago
comment:3 by , 2 years ago
| Resolution: | → fixed |
|---|---|
| Status: | assigned → closed |
Fixed at commit c125787335.
comment:4 by , 2 years ago
| Priority: | normal → elevated |
|---|
The security fix for the EXIF metadata parser is now known as CVE-2024-4453
The description is:
"Heap-based buffer overflow in the EXIF image tag parser when handling certain malformed streams before GStreamer 1.24.3 or 1.22.12.", and the impact is "It is possible for a malicious third party to trigger a crash in the application, and possibly also effect code execution through heap manipulation."
I'll file an SA for this later, I've got it on my list. :)
Note:
See TracTickets
for help on using tickets.

This release only contains bugfixes and it should be safe to update from 1.24.x.
Highlighted bugfixes in 1.24.3
gstreamer
gst-plugins-base
gst-plugins-good
gst-plugins-bad
gst-plugins-ugly
GStreamer Rust plugins
Fixed:
Added:
gst-libav
gst-rtsp-server
gstreamer-vaapi