gpp_maybe
Security update for gstreamer-plugins-good
SUSE-SLE-Module-Basesystem-15-SP6-2025-55
This update for gstreamer-plugins-good fixes the following issues: - CVE-2024-47606: Fixed an integer overflows in MP4/MOV demuxer and memory allocator that can lead to out-of-bounds writes. (boo#1234449) - CVE-2024-47537: Fixed an out-of-bounds write in isomp4/qtdemux.c. (boo#1234414) - CVE-2024-47539: Fixed an out-of-bounds write in convert_to_s334_1a. (boo#1234417) - CVE-2024-47530: Fixed an uninitialized stack memory in Matroska/WebM demuxer. (boo#1234421) - CVE-2024-47596: Fixed an integer underflow in MP4/MOV demuxer that can lead to out-of-bounds reads. (boo#1234424) - CVE-2024-47597: Fixed an out-of-bounds reads in MP4/MOV demuxer sample table parser (boo#1234425) - CVE-2024-47598: Fixed MP4/MOV sample table parser out-of-bounds read. (boo#1234426) - CVE-2024-47599: Fixed insufficient error handling in JPEG decoder that can lead to NULL-pointer dereferences. (boo#1234427) - CVE-2024-47601: Fixed a NULL-pointer dereference in Matroska/WebM demuxer. (boo#1234428) - CVE-2024-47602: Fixed a NULL-pointer dereferences and out-of-bounds reads in Matroska/WebM demuxer. (boo#1234432) - CVE-2024-47603: Fixed a NULL-pointer dereference in Matroska/WebM demuxer. (boo#1234433) - CVE-2024-47775: Fixed various out-of-bounds reads in WAV parser. (boo#1234434) - CVE-2024-47776: Fixed various out-of-bounds reads in WAV parser. (boo#1234435) - CVE-2024-47777: Fixed various out-of-bounds reads in WAV parser. (boo#1234436) - CVE-2024-47778: Fixed various out-of-bounds reads in WAV parser. (boo#1234439) - CVE-2024-47834: Fixed a use-after-free in the Matroska demuxer that can cause crashes for certain input files. (boo#1234440) - CVE-2024-47774: Fixed an integer overflow in AVI subtitle parser that leads to out-of-bounds reads. (boo#1234446) - CVE-2024-47613: Fixed a NULL-pointer dereference in gdk-pixbuf decoder. (boo#1234447) - CVE-2024-47543: Fixed an out-of-bounds write in qtdemux_parse_container. (boo#1234462) - CVE-2024-47544: Fixed a NULL-pointer dereferences in MP4/MOV demuxer CENC handling. (boo#1234473) - CVE-2024-47545: Fixed an integer underflow in FOURCC_strf parsing leading to out-of-bounds read. (boo#1234476) - CVE-2024-47546: Fixed an integer underflow in extract_cc_from_data leading to out-of-bounds read. (boo#1234477)
-
Release DateJan 9 2025
-
ReferencesBugzilla: 1234435, 1234428, 1234425, 1234424, 1234477, 1234427, 1234447, 1234473, 1234433, 1234436, 1234426, 1234476, 1234446, 1234432, 1234440, 1234434, 1234417, 1234439, 1234421, 1234462, 1234414, 1234449
CVEs: CVE-2024-47774, CVE-2024-47545, CVE-2024-47603, CVE-2024-47778, CVE-2024-47544, CVE-2024-47598, CVE-2024-47596, CVE-2024-47530, CVE-2024-47546, CVE-2024-47537, CVE-2024-47834, CVE-2024-47602, CVE-2024-47543, CVE-2024-47613, CVE-2024-47606, CVE-2024-47601, CVE-2024-47539, CVE-2024-47597, CVE-2024-47599, CVE-2024-47776, CVE-2024-47775, CVE-2024-47777 -
Typesecurity
-
Severityimportant
cloud_download Downloads
Basesystem Module 15.6 aarch64
-
Packagesgstreamer-plugins-good
GStreamer Streaming-Media Framework Plug-Insgstreamer-plugins-good-lang1.24.0-150600.3.3.1 lock rpm lock src
Translations for package gstreamer-plugins-good1.24.0-150600.3.3.1 lock rpm
Basesystem Module 15.6 ppc64le
-
Packagesgstreamer-plugins-good
GStreamer Streaming-Media Framework Plug-Insgstreamer-plugins-good-lang1.24.0-150600.3.3.1 lock rpm lock src
Translations for package gstreamer-plugins-good1.24.0-150600.3.3.1 lock rpm
Basesystem Module 15.6 s390x
-
Packagesgstreamer-plugins-good
GStreamer Streaming-Media Framework Plug-Insgstreamer-plugins-good-lang1.24.0-150600.3.3.1 lock rpm lock src
Translations for package gstreamer-plugins-good1.24.0-150600.3.3.1 lock rpm
Basesystem Module 15.6 x86_64
-
Packagesgstreamer-plugins-good
GStreamer Streaming-Media Framework Plug-Insgstreamer-plugins-good-lang1.24.0-150600.3.3.1 lock rpm lock src
Translations for package gstreamer-plugins-good1.24.0-150600.3.3.1 lock rpm