First published: Wed May 29 2024(Updated: )
It was discovered that GStreamer Base Plugins incorrectly handled certain EXIF metadata. An attacker could possibly use this issue to execute arbitrary code or cause a crash.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/gstreamer1.0-plugins-base | <1.24.2-1ubuntu0.1 | 1.24.2-1ubuntu0.1 |
Ubuntu | =24.04 | |
All of | ||
ubuntu/gstreamer1.0-plugins-base | <1.22.6-1ubuntu0.1 | 1.22.6-1ubuntu0.1 |
Ubuntu | =23.10 | |
All of | ||
ubuntu/gstreamer1.0-plugins-base | <1.20.1-1ubuntu0.2 | 1.20.1-1ubuntu0.2 |
Ubuntu | =22.04 | |
All of | ||
ubuntu/gstreamer1.0-plugins-base | <1.16.3-0ubuntu1.3 | 1.16.3-0ubuntu1.3 |
Ubuntu | =20.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of USN-6798-1 is considered high as it involves potential execution of arbitrary code or application crashes.
To fix USN-6798-1, you need to update GStreamer Base Plugins to the appropriate remedial version for your Ubuntu release.
USN-6798-1 affects GStreamer Base Plugins versions prior to 1.24.2-1ubuntu0.1, 1.22.6-1ubuntu0.1, 1.20.1-1ubuntu0.2, and 1.16.3-0ubuntu1.3.
The impacted Ubuntu versions are 24.04, 23.10, 22.04, and 20.04.
If you cannot update to a fixed version for USN-6798-1, it's recommended to limit the use of the affected GStreamer Base Plugins or isolate the application leveraging these plugins.