Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 39: Advisory 2023-6a4aea6d13 Critical: GStreamer Buffer Overflow

fedora
Calendar Grey November 19, 2023
Dist Fedora Esm H88
The release of Gstreamer1-plugin-libav version 1.22.7 addresses several significant vulnerabilities in Fedora 39, bolstering its security mechanisms.
1.22.7

Summary

GStreamer is a streaming media framework, based on graphs of filters which

operate on media data. Applications using this library can do anything

from real-time sound processing to playing videos, and just about anything

else media-related. Its plugin-based architecture means that new data

types or processing capabilities can be added simply by installing new

plugins.

This package provides FFmpeg/LibAV GStreamer plugin.

Update Information:

1.22.7

Change Log

* Tue Nov 14 2023 Gwyn Ciesla - 1.22.7-1 - 1.22.7

References


[ 1 ] Bug #2250248 - CVE-2023-44429 gstreamer1-plugins-bad-free: gstreamer: AV1 codec parser buffer overflow [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2250248 [ 2 ] Bug #2250250 - CVE-2023-44446 gstreamer1-plugins-bad-free: gstreamer: MXF demuxer use-after-free vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2250250

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-6a4aea6d13' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: gstreamer1-plugin-libav
Product: Fedora 39
Version: 1.22.7
Release: 1.fc39
Summary: GStreamer FFmpeg/LibAV plugin

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here