Critical Security Advisory: Fedora 39 GStreamer Buffer Overflow Fix CVE-2024-0444
Summary
GStreamer is a streaming-media framework, based on graphs of filters
which operate on media data. Applications using this library can do
anything from real-time sound processing to playing videos, and just
about anything else media-related. Its plug-in-based architecture
means that new data types or processing capabilities can be added by
installing new plug-ins.
Update Information:
Update to gstreamer-1.22.9. Backport fix for CVE-2024-0444.
Change Log
* Sat Jan 27 2024 Sandro Mani
References
[ 1 ] Bug #2283001 - CVE-2024-4453 mingw-gstreamer1: gstreamer: EXIF Metadata Parsing Integer Overflow [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2283001
[ 2 ] Bug #2292337 - CVE-2024-0444 mingw-gstreamer1: gstreamer: AV1 Video Parsing Stack-based Buffer Overflow [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2292337
Update Instructions
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-919bc7e512' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label