Security Advisory 2023-0010
(ZDI-CAN-22299)
(CVE-2023-44446)
Summary |
MXF demuxer use-after-free |
Date |
2023-11-13 12:00 |
Affected Versions |
GStreamer gst-plugins-bad < 1.22.7 |
ID |
GStreamer-SA-2023-0010 |
|
ZDI-CAN-22299 |
|
CVE-2023-44446 |
|
Details
Use-after-free (read) in the MXF demuxer when handling certain files before GStreamer 1.22.7
Impact
It is possible for a malicious third party to trigger a crash in the application.
Threat mitigation
Workarounds
Solution
The gst-plugins-bad 1.22.7 releases address the issue. People using older branches of GStreamer should apply the patch and recompile.
References
The GStreamer project
CVE Database Entries
GStreamer 1.22.7 release
Patches