CVE-2024-47544: GHSL-2024-238: Null pointer dereference in qtdemux_parse_sbgp in GStreamer - CVE-2024-47544
Published Dec 11, 2024
·Updated
GStreamer is a library for constructing graphs of media-handling components. The function qtdemuxparsesbgp in qtdemux.c is affected by a null dereference vulnerability. This vulnerability is fixed in 1.24.10.
Affected Software
3 affected componentsFixes available
Gstreamer Project Gstreamer<1.24.10
debian/gst-plugins-good1.0<=1.18.4-2+deb11u2
1.18.4-2+deb11u31.22.0-5+deb12u21.26.0-1
GStreamer GStreamer<1.24.10
Remediation
Event History
Dec 11, 2024
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
DescriptionAffected Software
CVE Published
via MITRE·06:57 PM
Data Sourced
via MITRE·06:57 PM
DescriptionWeakness
Dec 12, 2024
Data Sourced
via NVD·02:03 AM
RemedyDescriptionSeverityWeaknessAffected Software
Dec 22, 2024
Data Sourced
via Ubuntu·03:20 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-47544?
The severity of CVE-2024-47544 is considered to be high due to the potential for a null dereference leading to application crashes.
2
How do I fix CVE-2024-47544?
To fix CVE-2024-47544, update GStreamer to version 1.24.10 or later.
3
Which versions of GStreamer are affected by CVE-2024-47544?
GStreamer versions prior to 1.24.10 are affected by CVE-2024-47544.
4
Can I still use GStreamer 1.24.9 with CVE-2024-47544?
Using GStreamer 1.24.9 is not recommended as it contains the vulnerability CVE-2024-47544.
5
What components are affected in the GStreamer library by CVE-2024-47544?
CVE-2024-47544 specifically affects the qtdemux component in the GStreamer library.