Lucene search

K
oraclelinuxOracleLinuxELSA-2023-7791
HistoryDec 15, 2023 - 12:00 a.m.

gstreamer1-plugins-bad-free security update

2023-12-1500:00:00
linux.oracle.com
9
gstreamer1-plugins-bad-free
security update
heap-based buffer overflow
use-after-free
cve-2023-44429
cve-2023-44446
av1 codec parser
mxf demuxer
rhel-17030
rhel-17039

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

7.5 High

AI Score

Confidence

Low

0.0005 Low

EPSS

Percentile

16.2%

[1.22.1-2]

  • Patch CVE-2023-44429: AV1 codec parser heap-based buffer overflow
  • Patch CVE-2023-44446: MXF demuxer use-after-free
  • Resolves: RHEL-17030, RHEL-17039

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

7.5 High

AI Score

Confidence

Low

0.0005 Low

EPSS

Percentile

16.2%