GStreamer AV1 Codec Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation.
The specific flaw exists within the parsing of AV1 encoded video files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22226.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade gstreamer1-plugins-bad-free-develUpgrade gstreamer1-plugins-bad-free | Dec 19, 2023 | Dec 13, 2023 |
| Alpine Linux | — | Upgrade gstreamerUpgrade gst-plugins-bad | Aug 22, 2024 | May 3, 2024 |
| Amazon Linux Ami 2 | — | Upgrade gstreamer1-plugins-bad-freeUpgrade gstreamer1-plugins-bad-free-debuginfoUpgrade gstreamer1-plugins-bad-free-devel | Dec 5, 2023 | Dec 5, 2023 |
| Centos_linux | — | Upgrade gstreamer1-plugins-bad-freeUpgrade gstreamer1-plugins-bad-free-debugsourceUpgrade gstreamer1-plugins-bad-free-debuginfo | Dec 14, 2023 | Dec 13, 2023 |
| Debian | — | Upgrade gst-plugins-bad1.0 | Dec 4, 2023 | Dec 4, 2023 |
| Gentoo Linux | — | Upgrade media-libs/gstreamer.Upgrade media-libs/gst-plugins-bad. | Jul 1, 2024 | May 3, 2024 |
| Oracle_linux | — | Upgrade gstreamer1-plugins-bad-free-develUpgrade gstreamer1-plugins-bad-free | May 21, 2024 | Nov 13, 2023 |
| Redhat_linux | — | Upgrade gstreamer1-plugins-bad-free-debuginfoUpgrade gstreamer1-plugins-bad-freeUpgrade gstreamer1-plugins-bad-free-debugsourceUpgrade gstreamer1-plugins-bad-free-devel | Dec 14, 2023 | Dec 13, 2023 |
| Suse | — | Upgrade libgstisoff-1_0-0Upgrade typelib-1_0-gstcodecs-1_0Upgrade gstreamer-plugins-bad-langUpgrade libgstbasecamerabinsrc-1_0-0Upgrade libgsturidownloader-1_0-0Upgrade typelib-1_0-gstbadaudio-1_0Upgrade typelib-1_0-GstCuda-1_0Upgrade typelib-1_0-gstmpegts-1_0Upgrade typelib-1_0-gstinsertbin-1_0Upgrade typelib-1_0-GstVa-1_0Upgrade libgstwebrtcnice-1_0-0Upgrade libgstvulkan-1_0-0Upgrade typelib-1_0-gstplayer-1_0Upgrade gstreamer-plugins-bad-develUpgrade libgstinsertbin-1_0-0Upgrade typelib-1_0-gstplay-1_0Upgrade libgstphotography-1_0-0Upgrade typelib-1_0-gstwebrtc-1_0Upgrade libgstsctp-1_0-0Upgrade libgstplay-1_0-0Upgrade libgstadaptivedemux-1_0-0Upgrade libgsttranscoder-1_0-0Upgrade libgstplayer-1_0-0Upgrade libgstcodecs-1_0-0Upgrade libgstcuda-1_0-0Upgrade libgstva-1_0-0Upgrade libgstwayland-1_0-0Upgrade typelib-1_0-CudaGst-1_0Upgrade libgstcodecparsers-1_0-0Upgrade libgstmpegts-1_0-0Upgrade libgstbadaudio-1_0-0Upgrade libgstwebrtc-1_0-0Upgrade gstreamer-plugins-badUpgrade gstreamer-plugins-bad-chromaprint | Dec 19, 2023 | Dec 14, 2023 |
| Ubuntu | — | Upgrade libgstreamer-plugins-bad1.0-0Upgrade gstreamer1.0-plugins-bad | Nov 30, 2023 | Nov 29, 2023 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | May 3, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub