USN-7807-1: GStreamer Base Plugins vulnerabilities

Publication date

7 October 2025

Overview

Several security issues were fixed in GStreamer Base Plugins.


Packages

Details

Michael Randrianantenaina discovered that GStreamer Base Plugins did not
correctly handle certain integer operations. An attacker could possibly
use this issue to execute arbitrary code. (CVE-2023-37327, CVE-2024-4453)

Michael Randrianantenaina discovered that GStreamer Base Plugins did not
correctly handle certain memory operations. An attacker could possibly
use this issue to execute arbitrary code. This issue only affected
Ubuntu 18.04 LTS. (CVE-2023-37328)

Antonio Morales discovered that GStreamer Base Plugins did not correctly
handle certain memory operations. An attacker could possibly use this
issue to execute arbitrary code. (CVE-2024-47538)

Antonio Morales discovered that GStreamer Base Plugins did not correctly
handle parsing certain inputs, which could lead to an...

Michael Randrianantenaina discovered that GStreamer Base Plugins did not
correctly handle certain integer operations. An attacker could possibly
use this issue to execute arbitrary code. (CVE-2023-37327, CVE-2024-4453)

Michael Randrianantenaina discovered that GStreamer Base Plugins did not
correctly handle certain memory operations. An attacker could possibly
use this issue to execute arbitrary code. This issue only affected
Ubuntu 18.04 LTS. (CVE-2023-37328)

Antonio Morales discovered that GStreamer Base Plugins did not correctly
handle certain memory operations. An attacker could possibly use this
issue to execute arbitrary code. (CVE-2024-47538)

Antonio Morales discovered that GStreamer Base Plugins did not correctly
handle parsing certain inputs, which could lead to an out-of-bounds access
vulnerability. An attacker could possibly use this issue to cause a denial
of service or execute arbitrary code. (CVE-2024-47541, CVE-2024-47615)

Antonio Morales discovered that GStreamer Base Plugins did not correctly
handle certain memory operations. An attacker could possibly use this
issue to cause a denial of service. (CVE-2024-47542, CVE-2024-47607,
CVE-2024-47835)

Antonio Morales discovered that GStreamer Base Plugins did not correctly
handle parsing certain inputs, which could lead to an out-of-bounds access
vulnerability. An attacker could possibly use this issue to cause a denial
of service or execute arbitrary code. This issue only affected
Ubuntu 18.04 LTS. (CVE-2024-47600)


Update instructions

In general, a standard system update will make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
18.04 LTS bionic libgstreamer-plugins-base1.0-0 –  1.14.5-0ubuntu1~18.04.3+esm1  
libgstreamer-plugins-base1.0-dev –  1.14.5-0ubuntu1~18.04.3+esm1  
16.04 LTS xenial libgstreamer-plugins-base1.0-0 –  1.8.3-1ubuntu0.3+esm2  
libgstreamer-plugins-base1.0-dev –  1.8.3-1ubuntu0.3+esm2  

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›