In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade AlmaLinux:8
gstreamer1-plugins-good
to version 0:1.16.1-5.el8_10 or higher.
This issue was patched in ALSA-2024:11299
.
Note: Versions mentioned in the description apply only to the upstream gstreamer1-plugins-good
package and not the gstreamer1-plugins-good
package as distributed by AlmaLinux
.
See How to fix?
for AlmaLinux:8
relevant fixed versions and status.
GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been identified in gst_gdk_pixbuf_dec_flush
within gstgdkpixbufdec.c
. This function invokes memcpy
, using out_pix
as the destination address. out_pix
is expected to point to the frame 0 from the frame structure, which is read from the input file. However, in certain situations, it can points to a NULL frame, causing the subsequent call to memcpy
to attempt writing to the null address (0x00), leading to a null pointer dereference. This vulnerability can result in a Denial of Service (DoS) by triggering a segmentation fault (SEGV). This vulnerability is fixed in 1.24.10.