Логотип exploitDog
bind:"BDU:2023-08260" OR bind:"CVE-2023-44429"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2023-08260" OR bind:"CVE-2023-44429"

Количество 10

Количество 10

fstec логотип

BDU:2023-08260

больше 1 года назад

Уязвимость парсера AV1 Codec анализа субтитров subparse мультимедийного фреймворка Gstreamer, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2023-44429

около 1 года назад

GStreamer AV1 Codec Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of AV1 encoded video files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22226.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2023-44429

больше 1 года назад

GStreamer AV1 Codec Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of AV1 encoded video files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22226.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2023-44429

около 1 года назад

GStreamer AV1 Codec Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of AV1 encoded video files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22226.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2023-44429

около 1 года назад

GStreamer AV1 Codec Parsing Heap-based Buffer Overflow Remote Code Exe ...

CVSS3: 8.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:4875-1

больше 1 года назад

Security update for gstreamer-plugins-bad

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:4874-1

больше 1 года назад

Security update for gstreamer-plugins-bad

EPSS: Низкий
github логотип

GHSA-6f7w-hx2c-cxpj

около 1 года назад

GStreamer AV1 Codec Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of AV1 encoded video files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22226.

CVSS3: 8.8
EPSS: Низкий
oracle-oval логотип

ELSA-2023-7791

больше 1 года назад

ELSA-2023-7791: gstreamer1-plugins-bad-free security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2024:0305-1

10 месяцев назад

Security update for gstreamer-plugins-bad

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2023-08260

Уязвимость парсера AV1 Codec анализа субтитров subparse мультимедийного фреймворка Gstreamer, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
4%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2023-44429

GStreamer AV1 Codec Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of AV1 encoded video files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22226.

CVSS3: 8.8
4%
Низкий
около 1 года назад
redhat логотип
CVE-2023-44429

GStreamer AV1 Codec Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of AV1 encoded video files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22226.

CVSS3: 8.8
4%
Низкий
больше 1 года назад
nvd логотип
CVE-2023-44429

GStreamer AV1 Codec Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of AV1 encoded video files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22226.

CVSS3: 8.8
4%
Низкий
около 1 года назад
debian логотип
CVE-2023-44429

GStreamer AV1 Codec Parsing Heap-based Buffer Overflow Remote Code Exe ...

CVSS3: 8.8
4%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2023:4875-1

Security update for gstreamer-plugins-bad

4%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2023:4874-1

Security update for gstreamer-plugins-bad

4%
Низкий
больше 1 года назад
github логотип
GHSA-6f7w-hx2c-cxpj

GStreamer AV1 Codec Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of AV1 encoded video files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22226.

CVSS3: 8.8
4%
Низкий
около 1 года назад
oracle-oval логотип
ELSA-2023-7791

ELSA-2023-7791: gstreamer1-plugins-bad-free security update (IMPORTANT)

больше 1 года назад
suse-cvrf логотип
openSUSE-SU-2024:0305-1

Security update for gstreamer-plugins-bad

10 месяцев назад

Уязвимостей на страницу