[Debian] High CVE: CVE-2023-37328 gst-plugins-base1.0: Heap-based buffer overflow

Bug #2033580 reported by Yue Tao
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
StarlingX
Fix Released
High
Wentao Zhang

Bug Description

CVE-2023-37328: https://nvd.nist.gov/vuln/detail/CVE-2023-37328

Base Score: High

Reference:

['libgstreamer-plugins-base1.0-0_1.18.4-2_amd64.deb===>libgstreamer-plugins-base1.0-0_1.18.4-2+deb11u1_amd64.deb']
https://www.debian.org/security/2023/dsa-5443
https://www.tenable.com/plugins/nessus/177887

CVE References

Yue Tao (wrytao)
tags: added: stx.9.0 stx.security
removed: stx.secu
summary: [Debian] High CVE: CVE-2023-37328 gst-plugins-base1.0: Heap-based buffer
- overflow [22.12]
+ overflow
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to tools (master)

Fix proposed to branch: master
Review: https://review.opendev.org/c/starlingx/tools/+/895242

Changed in starlingx:
status: Triaged → In Progress
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to tools (master)

Reviewed: https://review.opendev.org/c/starlingx/tools/+/895242
Committed: https://opendev.org/starlingx/tools/commit/609a63e1ac522058c98c10418c02e4f909786e5d
Submitter: "Zuul (22348)"
Branch: master

commit 609a63e1ac522058c98c10418c02e4f909786e5d
Author: Wentao Zhang <email address hidden>
Date: Fri Sep 15 10:23:17 2023 +0800

    Debian: package : fix CVE-2023-37328

    Upgrade libgstreamer-plugins-base1.0-0 to 1.18.4-2+deb11u1

    Refer to:
    https://nvd.nist.gov/vuln/detail/CVE-2023-37328

    Test Plan:
    Pass: downloader
    Pass: build-pkgs --clean --all
    Pass: build-image
    Pass: boot

    Closes-bug: #2033580

    Change-Id: Ia055896bc1252f0c304d5a2d059d62381e7b26ff
    Signed-off-by: Wentao Zhang <email address hidden>

Changed in starlingx:
status: In Progress → Fix Released
Ghada Khalil (gkhalil)
Changed in starlingx:
assignee: nobody → Wentao Zhang (wzhang4)
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.