
Cloud Vulnerability DB
A community-led vulnerabilities database
A use-after-free vulnerability (CVE-2023-44446) was discovered in the MXF demuxer component of GStreamer. The vulnerability affects GStreamer gst-plugins-bad versions prior to 1.22.7, disclosed on November 13, 2023. The flaw exists within the parsing of MXF video files and stems from the lack of validating the existence of an object prior to performing operations on it (GStreamer Advisory, ZDI Advisory).
The vulnerability is classified as a use-after-free (read) condition in the MXF demuxer when handling certain files. It has been assigned a CVSS v3.1 base score of 8.8 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. The vulnerability is tracked as CWE-416 (Use After Free) and requires user interaction to exploit, though it can be triggered remotely (NVD, Red Hat).
The vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. If successfully exploited, attackers can execute code in the context of the current process. The issue could allow a malicious third party to trigger a crash in the application and potentially achieve code execution (ZDI Advisory).
The vulnerability requires interaction with the GStreamer library to exploit, though attack vectors may vary depending on the implementation. The specific flaw is triggered through the parsing of malicious MXF video files. The vulnerability was initially reported to the vendor on October 19, 2023, and was publicly disclosed on November 15, 2023 (ZDI Advisory).
The vulnerability has been fixed in GStreamer gst-plugins-bad version 1.22.7. Users of older branches of GStreamer should apply the available patch and recompile their installations. Various Linux distributions have also released security updates to address this vulnerability (GStreamer Advisory, Red Hat).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."