CVE-2023-38103
Public on 2023-09-08
Modified on 2023-09-08
Description
ZDI-CAN-21443: Integer overflow leading to heap overwrite in RealMedia file handling
NOTE: https://gstreamer.freedesktop.org/security/sa-2023-0004.html
NOTE: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/issues/2782
NOTE: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/b268b27cd8ff0dda1fda71890cd414f4cb2096db
NOTE: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/4266ba0fd2be7702044a5d90a8215abe41709874 (1.22.5)
NOTE: https://www.zerodayinitiative.com/advisories/ZDI-23-1007/
DEBIANBUG: [1043501]
ADVISORIES: ['DSA-5476-1', 'DLA-3552-1']
NOTE: https://gstreamer.freedesktop.org/security/sa-2023-0004.html
NOTE: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/issues/2782
NOTE: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/b268b27cd8ff0dda1fda71890cd414f4cb2096db
NOTE: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/4266ba0fd2be7702044a5d90a8215abe41709874 (1.22.5)
NOTE: https://www.zerodayinitiative.com/advisories/ZDI-23-1007/
DEBIANBUG: [1043501]
ADVISORIES: ['DSA-5476-1', 'DLA-3552-1']
Severity
CVSS v3 Base Score
See breakdown
Affected Packages
Platform | Package | Release Date | Advisory | Status |
---|---|---|---|---|
Amazon Linux 2 - Core | gstreamer1-plugins-ugly-free | Not Affected |
CVSS Scores
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv3 | 7.7 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H |
NVD | CVSSv3 | 8.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |