Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-47542

Опубликовано: 11 дек. 2024
Источник: redhat
CVSS3: 6.2
EPSS Низкий

Описание

GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference has been discovered in the id3v2_read_synch_uint function, located in id3v2.c. If id3v2_read_synch_uint is called with a null work->hdr.frame_data, the pointer guint8 *data is accessed without validation, resulting in a null pointer dereference. This vulnerability can result in a Denial of Service (DoS) by triggering a segmentation fault (SEGV). This vulnerability is fixed in 1.24.10.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10gstreamer1-plugins-baseNot affected
Red Hat Enterprise Linux 7gstreamer1-plugins-baseOut of support scope
Red Hat Enterprise Linux 8gstreamer1-plugins-baseOut of support scope
Red Hat Enterprise Linux 9gstreamer1-plugins-baseFixedRHSA-2025:724313.05.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2331717gstreamer1-plugins-base: ID3v2 parser out-of-bounds read and NULL-pointer dereference

EPSS

Процентиль: 51%
0.00274
Низкий

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
6 месяцев назад

GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference has been discovered in the id3v2_read_synch_uint function, located in id3v2.c. If id3v2_read_synch_uint is called with a null work->hdr.frame_data, the pointer guint8 *data is accessed without validation, resulting in a null pointer dereference. This vulnerability can result in a Denial of Service (DoS) by triggering a segmentation fault (SEGV). This vulnerability is fixed in 1.24.10.

CVSS3: 7.5
nvd
6 месяцев назад

GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference has been discovered in the id3v2_read_synch_uint function, located in id3v2.c. If id3v2_read_synch_uint is called with a null work->hdr.frame_data, the pointer guint8 *data is accessed without validation, resulting in a null pointer dereference. This vulnerability can result in a Denial of Service (DoS) by triggering a segmentation fault (SEGV). This vulnerability is fixed in 1.24.10.

CVSS3: 7.5
debian
6 месяцев назад

GStreamer is a library for constructing graphs of media-handling compo ...

CVSS3: 7.5
fstec
6 месяцев назад

Уязвимость функции id3v2_read_synch_uint мультимедийного фреймворка Gstreamer, позволяющая нарушителю ваххаызвать отказ в обслуживании

oracle-oval
около 1 месяца назад

ELSA-2025-7243: gstreamer1-plugins-base security update (MODERATE)

EPSS

Процентиль: 51%
0.00274
Низкий

6.2 Medium

CVSS3