VDB

GCVE-VVD-MAGEIA-2024-119

GCVE-VVD-MAGEIA-2024-119
Advisory Published
Vulnetix · Advisory published April 3, 2024
Heap-based buffer overflow in the AV1 codec parser when handling certain malformed streams before GStreamer 1.22.9 It is possible for a malicious third party to trigger a crash in the application, and possibly also effect code execution through heap manipulation.

Affected Products

VendorProductVersionsPlatforms
Mageianodejs0 (affected), 20.12.0-1.mga9 (unaffected)
Mageiayarnpkg0 (affected), 1.22.22-0.10.5.0.1.mga9 (unaffected)
Mageiagstreamer1.00 (affected), 1.22.11-1.mga9 (unaffected), 0 (affected), 1.22.11-1.mga9 (unaffected)
Mageiagstreamer1.0-devtools0 (affected), 1.22.11-1.mga9 (unaffected), 0 (affected), 1.22.11-1.mga9 (unaffected)
Mageiagstreamer1.0-editing-services0 (affected), 1.22.11-1.mga9 (unaffected), 0 (affected), 1.22.11-1.mga9 (unaffected)
Mageiagstreamer1.0-libav0 (affected), 1.22.11-1.mga9 (unaffected), 0 (affected), 1.22.11-1.mga9 (unaffected)
Mageiagstreamer1.0-moodbar0 (affected), 1.3.0-1.mga9 (unaffected), 0 (affected), 1.3.0-1.mga9 (unaffected)
Mageiagstreamer1.0-omx0 (affected), 1.22.11-1.mga9 (unaffected), 0 (affected), 1.22.11-1.mga9 (unaffected)
Mageiagstreamer1.0-plugins-bad0 (affected), 1.22.11-1.mga9 (unaffected), 0 (affected), 1.22.11-1.mga9.tainted (unaffected), 0 (affected), 1.22.11-1.mga9 (unaffected), 0 (affected), 1.22.11-1.mga9.tainted (unaffected)
Mageiagstreamer1.0-plugins-base0 (affected), 1.22.11-1.mga9 (unaffected), 0 (affected), 1.22.11-1.mga9 (unaffected)
Mageiagstreamer1.0-plugins-good0 (affected), 1.22.11-1.mga9 (unaffected), 0 (affected), 1.22.11-1.mga9 (unaffected)
Mageiagstreamer1.0-plugins-ugly0 (affected), 1.22.11-1.mga9 (unaffected), 0 (affected), 1.22.11-1.mga9.tainted (unaffected), 0 (affected), 1.22.11-1.mga9 (unaffected), 0 (affected), 1.22.11-1.mga9.tainted (unaffected)
Mageiagstreamer1.0-python0 (affected), 1.22.11-1.mga9 (unaffected), 0 (affected), 1.22.11-1.mga9 (unaffected)
Mageiagstreamer1.0-rtsp-server0 (affected), 1.22.11-1.mga9 (unaffected), 0 (affected), 1.22.11-1.mga9 (unaffected)
Mageiagstreamer1.0-vaapi0 (affected), 1.22.11-1.mga9 (unaffected), 0 (affected), 1.22.11-1.mga9 (unaffected)

References

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›