First published: Fri Nov 17 2023(Updated: )
[MXF demuxer use-after-free]
Credit: zdi-disclosures@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/gstreamer-plugins-bad-free | <1.22.7 | 1.22.7 |
ubuntu/gst-plugins-bad1.0 | <1.16.3-0ubuntu1.1 | 1.16.3-0ubuntu1.1 |
ubuntu/gst-plugins-bad1.0 | <1.20.3-0ubuntu1.1 | 1.20.3-0ubuntu1.1 |
ubuntu/gst-plugins-bad1.0 | <1.22.1-1ubuntu1.1 | 1.22.1-1ubuntu1.1 |
ubuntu/gst-plugins-bad1.0 | <1.22.4-1ubuntu1.1 | 1.22.4-1ubuntu1.1 |
debian/gst-plugins-bad1.0 | <=1.14.4-1+deb10u2 | 1.14.4-1+deb10u5 1.18.4-3+deb11u4 1.22.0-4+deb12u5 1.22.10-1 1.24.2-3 |
GStreamer | <1.22.7 | |
GStreamer |
https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/274551d450e443a8c71baa95e3f8d5dad212737f
https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/7dfaa57b6f9b55f17ffe824bd8988bb71ae11353
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-44446 is a vulnerability in the MXF demuxer component of the gst-plugins-bad1.0 package, which can lead to a use-after-free issue.
The severity of CVE-2023-44446 is not specified in the provided information. Please refer to the references for more details.
The gst-plugins-bad1.0 package in Debian is affected by CVE-2023-44446.
To fix CVE-2023-44446, update to the fixed versions of the gst-plugins-bad1.0 package provided by Debian as mentioned in the remedy field of the affected software information.
You can find more information about CVE-2023-44446 in the references provided: [link1](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-44446), [link2](https://gstreamer.freedesktop.org/security/sa-2023-0010.html), [link3](https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/5635).