#19737 closed enhancement (fixed)
gstreamer-1.24.3 gst-plugins-base gst-plugins-good gst-plugins-bad gst-plugins-ugly gst-libav gstreamer-vaapi
Reported by: | Bruce Dubbs | Owned by: | Bruce Dubbs |
---|---|---|---|
Priority: | elevated | Milestone: | 12.2 |
Component: | BOOK | Version: | git |
Severity: | normal | Keywords: | |
Cc: |
Description ¶
New point version.
Change History (5)
comment:1 by , 11 months ago
Owner: | changed from | to
---|---|
Status: | new → assigned |
comment:2 by , 11 months ago
comment:3 by , 11 months ago
Resolution: | → fixed |
---|---|
Status: | assigned → closed |
Fixed at commit c125787335.
comment:4 by , 11 months ago
Priority: | normal → elevated |
---|
The security fix for the EXIF metadata parser is now known as CVE-2024-4453
The description is:
"Heap-based buffer overflow in the EXIF image tag parser when handling certain malformed streams before GStreamer 1.24.3 or 1.22.12.", and the impact is "It is possible for a malicious third party to trigger a crash in the application, and possibly also effect code execution through heap manipulation."
I'll file an SA for this later, I've got it on my list. :)
Note:
See TracTickets
for help on using tickets.
This release only contains bugfixes and it should be safe to update from 1.24.x.
Highlighted bugfixes in 1.24.3
gstreamer
gst-plugins-base
gst-plugins-good
gst-plugins-bad
gst-plugins-ugly
GStreamer Rust plugins
Fixed:
Added:
gst-libav
gst-rtsp-server
gstreamer-vaapi