{"id":"SUSE-SU-2023:4943-1","summary":"Security update for gstreamer-plugins-bad","details":"This update for gstreamer-plugins-bad fixes the following issues:\n\n- CVE-2023-40475: Fixed GStreamer MXF File Parsing Integer Overflow (bsc#1215792).\n- CVE-2023-44446: Fixed GStreamer MXF File Parsing Use-After-Free (bsc#1217213).\n","modified":"2026-02-04T04:18:25.012966Z","published":"2023-12-21T11:33:54Z","related":["CVE-2023-40475","CVE-2023-44446"],"upstream":["CVE-2023-40475","CVE-2023-44446"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2023/suse-su-20234943-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1215792"},{"type":"REPORT","url":"https://bugzilla.suse.com/1217213"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-40475"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-44446"}],"affected":[{"package":{"name":"gstreamer-plugins-bad","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP5","purl":"pkg:rpm/suse/gstreamer-plugins-bad&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.22.0-150500.3.17.1"}]}],"ecosystem_specific":{"binaries":[{"libgstphotography-1_0-0":"1.22.0-150500.3.17.1","libgstplay-1_0-0":"1.22.0-150500.3.17.1","libgstplayer-1_0-0":"1.22.0-150500.3.17.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:4943-1.json"}},{"package":{"name":"gstreamer-plugins-bad","ecosystem":"SUSE:Linux Enterprise Module for Desktop Applications 15 SP5","purl":"pkg:rpm/suse/gstreamer-plugins-bad&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.22.0-150500.3.17.1"}]}],"ecosystem_specific":{"binaries":[{"libgstadaptivedemux-1_0-0":"1.22.0-150500.3.17.1","libgstcodecparsers-1_0-0":"1.22.0-150500.3.17.1","libgstcodecs-1_0-0":"1.22.0-150500.3.17.1","libgstwebrtc-1_0-0":"1.22.0-150500.3.17.1","typelib-1_0-GstCuda-1_0":"1.22.0-150500.3.17.1","gstreamer-plugins-bad-chromaprint":"1.22.0-150500.3.17.1","typelib-1_0-GstPlay-1_0":"1.22.0-150500.3.17.1","typelib-1_0-GstInsertBin-1_0":"1.22.0-150500.3.17.1","libgstvulkan-1_0-0":"1.22.0-150500.3.17.1","typelib-1_0-CudaGst-1_0":"1.22.0-150500.3.17.1","libgstbasecamerabinsrc-1_0-0":"1.22.0-150500.3.17.1","libgstmpegts-1_0-0":"1.22.0-150500.3.17.1","typelib-1_0-GstBadAudio-1_0":"1.22.0-150500.3.17.1","typelib-1_0-GstMpegts-1_0":"1.22.0-150500.3.17.1","typelib-1_0-GstWebRTC-1_0":"1.22.0-150500.3.17.1","libgstisoff-1_0-0":"1.22.0-150500.3.17.1","libgstva-1_0-0":"1.22.0-150500.3.17.1","libgstwayland-1_0-0":"1.22.0-150500.3.17.1","typelib-1_0-GstVa-1_0":"1.22.0-150500.3.17.1","gstreamer-plugins-bad-devel":"1.22.0-150500.3.17.1","gstreamer-plugins-bad":"1.22.0-150500.3.17.1","libgstinsertbin-1_0-0":"1.22.0-150500.3.17.1","libgstsctp-1_0-0":"1.22.0-150500.3.17.1","libgsttranscoder-1_0-0":"1.22.0-150500.3.17.1","libgsturidownloader-1_0-0":"1.22.0-150500.3.17.1","typelib-1_0-GstCodecs-1_0":"1.22.0-150500.3.17.1","gstreamer-plugins-bad-lang":"1.22.0-150500.3.17.1","libgstbadaudio-1_0-0":"1.22.0-150500.3.17.1","libgstcuda-1_0-0":"1.22.0-150500.3.17.1","libgstwebrtcnice-1_0-0":"1.22.0-150500.3.17.1","typelib-1_0-GstPlayer-1_0":"1.22.0-150500.3.17.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:4943-1.json"}},{"package":{"name":"gstreamer-plugins-bad","ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP5","purl":"pkg:rpm/suse/gstreamer-plugins-bad&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.22.0-150500.3.17.1"}]}],"ecosystem_specific":{"binaries":[{"libgsttranscoder-1_0-0":"1.22.0-150500.3.17.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:4943-1.json"}}],"schema_version":"1.7.3"}