First published: Fri Nov 17 2023(Updated: )
[AV1 codec parser buffer overflow]
Credit: zdi-disclosures@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/gstreamer-plugins-bad-free | <1.22.7 | 1.22.7 |
GStreamer GStreamer | ||
ubuntu/gst-plugins-bad1.0 | <1.20.3-0ubuntu1.1 | 1.20.3-0ubuntu1.1 |
ubuntu/gst-plugins-bad1.0 | <1.22.1-1ubuntu1.1 | 1.22.1-1ubuntu1.1 |
ubuntu/gst-plugins-bad1.0 | <1.22.4-1ubuntu1.1 | 1.22.4-1ubuntu1.1 |
debian/gst-plugins-bad1.0 | 1.14.4-1+deb10u2 1.14.4-1+deb10u5 1.18.4-3+deb11u4 1.22.0-4+deb12u5 1.22.10-1 1.24.2-3 | |
Gstreamer Project Gstreamer | <1.22.7 |
https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/1db83d3f745332cbda6adf954b2c53a10caa205e
https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/b76a801f57353b893c344025cac56413140fca6d
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-44429 is a vulnerability related to a buffer overflow in the AV1 codec parser.
The severity of CVE-2023-44429 is not specified.
If you are using vulnerable versions of the gst-plugins-bad1.0 package on Debian, you may be vulnerable to this buffer overflow vulnerability.
To fix CVE-2023-44429, you should update the gst-plugins-bad1.0 package to a version that includes the appropriate remedy.
You can find more information about CVE-2023-44429 on the MITRE CVE website and the GStreamer security advisory.