Bugzilla – Bug 1219453
VUL-0: CVE-2024-0444: gstreamer-plugins-bad: AV1 codec parser potential buffer overflow during tile list parsing (ZDI-CAN-22300)
Last modified: 2024-05-02 18:02:59 UTC
Heap-based buffer overflow in the AV1 codec parser when handling certain malformed streams before GStreamer 1.22.9 Impact It is possible for a malicious third party to trigger a crash in the application, and possibly also effect code execution through heap manipulation. Threat mitigation Workarounds Solution The gst-plugins-bad 1.22.9 releases address the issue. People using older branches of GStreamer should apply the patch and recompile. References: https://gstreamer.freedesktop.org/security/sa-2024-0001.html
Only AV1 supported versions are affected: - SUSE:SLE-15-SP4:Update - SUSE:SLE-15-SP5:Update - SUSE:ALP:Source:Standard:1.0