USN-8205-1
Dashboard / Vulnerabilities / USN-8205-1
USN-8205-1
Summary: gst-plugins-bad1.0 vulnerabilities
Details: It was discovered that multiple plugins in GStreamer contained arithmetic overflows. An attacker could possibly use this issue to cause applications using the plugins to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2023-37329, CVE-2023-40474, CVE-2023-40475, CVE-2023-40476) It was discovered that the MXF demuxer plugin in GStreamer did not properly manage memory. An attacker could possibly use this issue to cause applications using the plugin to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2023-44446) It was discovered that the H265 codec plugin in GStreamer could be made to write out of bounds. An attacker could possibly use this issue to cause applications using the plugin to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2025-3887)
References: https://ubuntu.com/security/notices/USN-8205-1, https://ubuntu.com/security/CVE-2023-37329, https://ubuntu.com/security/CVE-2023-40474, https://ubuntu.com/security/CVE-2023-40475, https://ubuntu.com/security/CVE-2023-40476, https://ubuntu.com/security/CVE-2023-44446, https://ubuntu.com/security/CVE-2025-3887
Affected packages
Package
Name: gst-plugins-bad1.0
Purl: pkg:deb/ubuntu/gst-plugins-bad1.0?arch=source&distro=esm-apps%2Fxenial
Affected ranges
Type: ECOSYSTEM
Events:
