<?xml version="1.0" encoding="utf-8"?>
  <?xml-stylesheet type="text/xsl" href="sa-render.xsl"?>
  <update from="huaweicloud.com" type="security" status="stable" version="1">
    <id>HCE2-SA-2024-0078</id>
    <title>An update for gstreamer1-plugins-bad-free is now available for HCE 2.0</title>
    <severity>Important</severity>
    <release>HCE 2.0</release>
    <issued date="2024-03-26 06:00:41"/>
    <updated date="2024-03-26 06:00:41"/>
    <references>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2023-44446" id="CVE-2023-44446" title="CVE-2023-44446 Base Score: 8.8 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2023-37329" id="CVE-2023-37329" title="CVE-2023-37329 Base Score: 5.5 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" type="cve"/>
    </references>
    <description>Security Fix(es):

The Oracle Linux Bulletin lists all CVEs that had been resolved and announced in Oracle Linux Security Advisories (ELSA) in the last one month prior to the release of the bulletin. Oracle Linux Bulletins are published on the same day as Oracle Critical Patch Updates are released. These bulletins will also be updated for the following two months after their release (i.e., the two months between the normal quarterly Critical Patch Update publication dates) to cover all CVEs that had been resolved in those two months following the bulletin's publication. In addition, Oracle Linux Bulletins may also be updated for vulnerability issues deemed too critical to wait for the next scheduled bulletin publication date. (CVE-2023-44446)

A heap-based buffer overflow vulnerability was found in the PGS Blu-ray subtitle decoder within GStreamer when processing specific files. This issue could allow a malicious third party to crash the application and execute code by manipulating the heap. (CVE-2023-37329)
</description>
    <pkglist>
      <collection short="HCE 2.0" package="gstreamer1-plugins-bad-free">
        <name>HCE 2.0</name>
        <package arch="aarch64" name="gstreamer1-plugins-bad-free" version="1.16.2" release="9.hce2">
          <filename>gstreamer1-plugins-bad-free-1.16.2-9.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="gstreamer1-plugins-bad-free-devel" version="1.16.2" release="9.hce2">
          <filename>gstreamer1-plugins-bad-free-devel-1.16.2-9.hce2.aarch64.rpm</filename>
        </package>
        <package arch="x86_64" name="gstreamer1-plugins-bad-free" version="1.16.2" release="9.hce2">
          <filename>gstreamer1-plugins-bad-free-1.16.2-9.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="gstreamer1-plugins-bad-free-devel" version="1.16.2" release="9.hce2">
          <filename>gstreamer1-plugins-bad-free-devel-1.16.2-9.hce2.x86_64.rpm</filename>
        </package>
      </collection>
    </pkglist>
  </update>
