RHSA-2024:11344: Important: gstreamer1-plugins-base and gstreamer1-plugins-good security update
GStreamer is a streaming media framework based on graphs of filters which operate on media data. The gstreamer1-plugins-base packages contain a collection of well-maintained base plug-ins.<br>Security Fix(es):<br><li> gstreamer1-plugins-good: uninitialized stack memory in Matroska/WebM demuxer (CVE-2024-47540)</li> <li> gstreamer1-plugins-good: OOB-write in isomp4/qtdemux.c (CVE-2024-47537)</li> <li> gstreamer1-plugins-base: GStreamer has a stack-buffer overflow in vorbishandleidentificationpacket (CVE-2024-47538)</li> <li> gstreamer1-plugins-base: out-of-bounds write in Ogg demuxer (CVE-2024-47615)</li> <li> gstreamer1-plugins-good: null pointer dereference in gstgdkpixbufdecflush (CVE-2024-47613)</li> <li> gstreamer1-plugins-base: stack-buffer overflow in gstopusdecparseheader (CVE-2024-47607)</li> <li> gstreamer1-plugins-good: integer overflows in MP4/MOV demuxer and memory allocator that can lead to out-of-bounds writes (CVE-2024-47606)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Other sources
Important: gstreamer1-plugins-base and gstreamer1-plugins-good security update
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:11344?
The severity of RHSA-2024:11344 is classified as important due to a vulnerability in GStreamer that could lead to uninitialized memory exposure.
How do I fix RHSA-2024:11344?
To fix RHSA-2024:11344, update the gstreamer1-plugins-base and gstreamer1-plugins-good packages to version 1.10.4-3.el7_9.
What products are affected by RHSA-2024:11344?
RHSA-2024:11344 affects various versions of Red Hat Enterprise Linux Server, particularly those running the Extended Life Cycle Support.
Is there a workaround for RHSA-2024:11344?
Currently, there are no known workarounds for RHSA-2024:11344, so it is recommended to apply the updates.
What specific packages are involved in RHSA-2024:11344?
The specific packages involved in RHSA-2024:11344 are gstreamer1-plugins-base and gstreamer1-plugins-good.