CVE-2024-47602: GHSL-2024-250: Null pointer dereference in gst_matroska_demux_add_wvpk_header in GStreamer - CVE-2024-47602
GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been discovered in the gstmatroskademuxaddwvpkheader function within matroska-demux.c. This function does not properly check the validity of the stream->codecpriv pointer in the following code. If stream->codecpriv is NULL, the call to GSTREADUINT16LE will attempt to dereference a null pointer, leading to a crash of the application. This vulnerability is fixed in 1.24.10.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-47602?
CVE-2024-47602 has been classified as a medium severity vulnerability.
How do I fix CVE-2024-47602?
To fix CVE-2024-47602, update the affected GStreamer packages to the recommended versions or later.
Which software is affected by CVE-2024-47602?
CVE-2024-47602 affects specific versions of the GStreamer library, particularly versions up to 1.24.10 and the gst-plugins-good1.0 package before 1.22.0-5+deb12u2.
What type of vulnerability is CVE-2024-47602?
CVE-2024-47602 is a null pointer dereference vulnerability found in the gst_matroska_demux_add_wvpk_header function.
Is CVE-2024-47602 exploitable?
Yes, CVE-2024-47602 is potentially exploitable, leading to application crashes or unintended behavior in media processing.