ELA-1015-1 gst-plugins-bad1.0 security update

use after free

2023-11-30
Packagegst-plugins-bad1.0
Version1.4.4-2.1+deb8u7 (jessie), 1.10.4-1+deb9u5 (stretch)
Related CVEs CVE-2023-44446


An issue has been found in gst-plugins-bad1.0, which contains several GStreamer plugins from the “bad” set. The issue is related to use-after-free of some pointers within the MXF demuxer.



For Debian 8 jessie, these problems have been fixed in version 1.4.4-2.1+deb8u7.

For Debian 9 stretch, these problems have been fixed in version 1.10.4-1+deb9u5.

We recommend that you upgrade your gst-plugins-bad1.0 packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.