CVE-2023-38104

Public on 2023-09-08
Modified on 2023-09-08
Description
ZDI-CAN-21444: Integer overflow leading to heap overwrite in RealMedia file handling

NOTE: https://gstreamer.freedesktop.org/security/sa-2023-0005.html
NOTE: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/issues/2782
NOTE: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/67e38cf47b7683586c24de18d8253029042dc72f
NOTE: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/eb89e0a13eeb59fc5bab787ded50faf6a50087e3 (1.22.5)
NOTE: https://www.zerodayinitiative.com/advisories/ZDI-23-1008/
DEBIANBUG: [1043501]
ADVISORIES: ['DSA-5476-1', 'DLA-3552-1']
Severity
Important severity
Important
CVSS v3 Base Score
7.7
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core gstreamer1-plugins-ugly-free Not Affected

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 7.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H
NVD CVSSv3 8.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H