RHSA-2024:11344HighCVSS 9.8
Red Hat Security Advisory: gstreamer1-plugins-base and gstreamer1-plugins-good security update
🔗 CVE IDs covered (7)
📋 Description
CVE-2024-47537 — gstreamer1-plugins-good: OOB-write in isomp4/qtdemux.c CVE-2024-47538 — gstreamer1-plugins-base: GStreamer has a stack-buffer overflow in vorbis_handle_identification_packet CVE-2024-47540 — gstreamer1-plugins-good: uninitialized stack memory in Matroska/WebM demuxer CVE-2024-47606 — gstreamer1-plugins-good: integer overflows in MP4/MOV demuxer and memory allocator that can lead to out-of-bounds writes CVE-2024-47607 — gstreamer1-plugins-base: stack-buffer overflow in gst_opus_dec_parse_header CVE-2024-47613 — gstreamer1-plugins-good: null pointer dereference in gst_gdk_pixbuf_dec_flush CVE-2024-47615 — gstreamer1-plugins-base: out-of-bounds write in Ogg demuxer
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2024:11344
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2331719
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2331722
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2331727
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2331740
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2331753
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2331754
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2331760
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_11344.json