CVE-2024-47542

GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference has been discovered in the id3v2_read_synch_uint function, located in id3v2.c. If id3v2_read_synch_uint is called with a null work->hdr.frame_data, the pointer guint8 *data is accessed without validation, resulting in a null pointer dereference. This vulnerability can result in a Denial of Service (DoS) by triggering a segmentation fault (SEGV). This vulnerability is fixed in 1.24.10.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gstreamer_project:gstreamer:*:*:*:*:*:*:*:*

History

13 Dec 2024, 19:03

Type Values Removed Values Added
Summary
  • (es) GStreamer es una librería para construir gráficos de componentes de manejo de medios. Se ha descubierto una desreferencia de puntero nulo en la función id3v2_read_synch_uint, ubicada en id3v2.c. Si se llama a id3v2_read_synch_uint con un work->hdr.frame_data nulo, se accede al puntero guint8 *data sin validación, lo que da como resultado una desreferencia de puntero nulo. Esta vulnerabilidad puede resultar en una denegación de servicio (DoS) al activar un error de segmentación (SEGV). Esta vulnerabilidad se corrigió en 1.24.10.
References () https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/8033.patch - () https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/8033.patch - Patch
References () https://gstreamer.freedesktop.org/security/sa-2024-0008.html - () https://gstreamer.freedesktop.org/security/sa-2024-0008.html - Patch, Release Notes, Third Party Advisory
References () https://securitylab.github.com/advisories/GHSL-2024-235_Gstreamer/ - () https://securitylab.github.com/advisories/GHSL-2024-235_Gstreamer/ - Exploit, Third Party Advisory
First Time Gstreamer Project gstreamer
Gstreamer Project
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CPE cpe:2.3:a:gstreamer_project:gstreamer:*:*:*:*:*:*:*:*

12 Dec 2024, 02:03

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-12 02:03

Updated : 2024-12-13 19:03


NVD link : CVE-2024-47542

Mitre link : CVE-2024-47542

CVE.ORG link : CVE-2024-47542


JSON object : View

Products Affected

gstreamer_project

  • gstreamer
CWE
CWE-125

Out-of-bounds Read

CWE-476

NULL Pointer Dereference