CVE-2024-47599

GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been discovered in the gst_jpeg_dec_negotiate function in gstjpegdec.c. This function does not check for a NULL return value from gst_video_decoder_set_output_state. When this happens, dereferences of the outstate pointer will lead to a null pointer dereference. This vulnerability can result in a Denial of Service (DoS) by triggering a segmentation fault (SEGV). This vulnerability is fixed in 1.24.10.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gstreamer_project:gstreamer:*:*:*:*:*:*:*:*

History

18 Dec 2024, 21:41

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
Summary
  • (es) GStreamer es una librería para construir gráficos de componentes de manejo de medios. Se ha descubierto una vulnerabilidad de desreferencia de puntero nulo en la función gst_jpeg_dec_negotiate en gstjpegdec.c. Esta función no comprueba si hay un valor de retorno NULL de gst_video_decoder_set_output_state. Cuando esto sucede, las desreferencias del puntero de estado externo darán lugar a una desreferencia de puntero nulo. Esta vulnerabilidad puede provocar una denegación de servicio (DoS) al activar un error de segmentación (SEGV). Esta vulnerabilidad se solucionó en la versión 1.24.10.
First Time Gstreamer Project gstreamer
Gstreamer Project
CPE cpe:2.3:a:gstreamer_project:gstreamer:*:*:*:*:*:*:*:*
References () https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/8040.patch - () https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/8040.patch - Patch
References () https://gstreamer.freedesktop.org/security/sa-2024-0016.html - () https://gstreamer.freedesktop.org/security/sa-2024-0016.html - Release Notes
References () https://securitylab.github.com/advisories/GHSL-2024-247_Gstreamer/ - () https://securitylab.github.com/advisories/GHSL-2024-247_Gstreamer/ - Third Party Advisory

12 Dec 2024, 02:03

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-12 02:03

Updated : 2024-12-18 21:41


NVD link : CVE-2024-47599

Mitre link : CVE-2024-47599

CVE.ORG link : CVE-2024-47599


JSON object : View

Products Affected

gstreamer_project

  • gstreamer
CWE
CWE-476

NULL Pointer Dereference