rpm package
opensuse/gstreamer-plugins-base&distro=openSUSE Leap 15.4
pkg:rpm/opensuse/gstreamer-plugins-base&distro=openSUSE%20Leap%2015.4
Vulnerabilities (3)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2023-37328 | — | < 1.20.1-150400.3.3.1 | 1.20.1-150400.3.3.1 | May 3, 2024 | GStreamer PGS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but atta | ||
| CVE-2023-37327 | — | < 1.20.1-150400.3.3.1 | 1.20.1-150400.3.3.1 | May 3, 2024 | GStreamer FLAC File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vector | ||
| CVE-2021-3522 | Med | 5.5 | < 1.16.3-150200.4.6.2 | 1.16.3-150200.4.6.2 | Jun 2, 2021 | GStreamer before 1.18.4 may perform an out-of-bounds read when handling certain ID3v2 tags. |
- CVE-2023-37328May 3, 2024affected < 1.20.1-150400.3.3.1fixed 1.20.1-150400.3.3.1
GStreamer PGS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but atta
- CVE-2023-37327May 3, 2024affected < 1.20.1-150400.3.3.1fixed 1.20.1-150400.3.3.1
GStreamer FLAC File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vector
- affected < 1.16.3-150200.4.6.2fixed 1.16.3-150200.4.6.2
GStreamer before 1.18.4 may perform an out-of-bounds read when handling certain ID3v2 tags.