DEBIAN-CVE-2024-47537

Source
https://security-tracker.debian.org/tracker/CVE-2024-47537
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-47537.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2024-47537
Upstream
Published
2024-12-12T02:03:27Z
Modified
2025-09-19T07:35:17.421109Z
Summary
[none]
Details

GStreamer is a library for constructing graphs of media-handling components. The program attempts to reallocate the memory pointed to by stream->samples to accommodate stream->nsamples + samplescount elements of type QtDemuxSample. The problem is that samplescount is read from the input file. And if this value is big enough, this can lead to an integer overflow during the addition. As a consequence, gtryrenew might allocate memory for a significantly smaller number of elements than intended. Following this, the program iterates through samplescount elements and attempts to write samples_count number of elements, potentially exceeding the actual allocated memory size and causing an OOB-write. This vulnerability is fixed in 1.24.10.

References

Affected packages

Debian:11 / gst-plugins-good1.0

Package

Name
gst-plugins-good1.0
Purl
pkg:deb/debian/gst-plugins-good1.0?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.18.4-2+deb11u3

Affected versions

1.*

1.18.4-2
1.18.4-2+deb11u1
1.18.4-2+deb11u2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / gst-plugins-good1.0

Package

Name
gst-plugins-good1.0
Purl
pkg:deb/debian/gst-plugins-good1.0?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.22.0-5+deb12u2

Affected versions

1.*

1.22.0-5
1.22.0-5+deb12u1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / gst-plugins-good1.0

Package

Name
gst-plugins-good1.0
Purl
pkg:deb/debian/gst-plugins-good1.0?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.24.10-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:14 / gst-plugins-good1.0

Package

Name
gst-plugins-good1.0
Purl
pkg:deb/debian/gst-plugins-good1.0?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.24.10-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}