USN-6268-1: GStreamer Base Plugins vulnerabilities
It was discovered that GStreamer Base Plugins incorrectly handled certain FLAC image tags. A remote attacker could use this issue to cause GStreamer Base Plugins to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2023-37327) It was discovered that GStreamer Base Plugins incorrectly handled certain subtitles. A remote attacker could use this issue to cause GStreamer Base Plugins to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2023-37328)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6268-1?
The severity of USN-6268-1 is critical due to its potential to cause denial of service and execute arbitrary code.
How do I fix USN-6268-1?
To fix USN-6268-1, upgrade to the corrected versions of gstreamer1.0-plugins-base: 1.22.1-1ubuntu1.1 for Ubuntu 23.04, 1.20.1-1ubuntu0.1 for Ubuntu 22.04, or 1.16.3-0ubuntu1.2 for Ubuntu 20.04.
What are the affected versions in USN-6268-1?
The affected versions in USN-6268-1 are prior to 1.22.1-1ubuntu1.1 for Ubuntu 23.04, 1.20.1-1ubuntu0.1 for Ubuntu 22.04, and 1.16.3-0ubuntu1.2 for Ubuntu 20.04.
Can USN-6268-1 lead to remote code execution?
Yes, USN-6268-1 can potentially lead to remote code execution if exploited by an attacker.
Which software is impacted by USN-6268-1?
GStreamer Base Plugins, specifically the gstreamer1.0-plugins-base package, is impacted by USN-6268-1.