Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.10.2025.0040
Category:Mageia Linux Local Security Checks
Title:Mageia: Security Advisory (MGASA-2025-0040)
Summary:The remote host is missing an update for the 'gstreamer1.0, gstreamer1.0-plugins-base, gstreamer1.0-plugins-good' package(s) announced via the MGASA-2025-0040 advisory.
Description:Summary:
The remote host is missing an update for the 'gstreamer1.0, gstreamer1.0-plugins-base, gstreamer1.0-plugins-good' package(s) announced via the MGASA-2025-0040 advisory.

Vulnerability Insight:
GStreamer has an OOB-write in isomp4/qtdemux.c. (CVE-2024-47537)
GStreamer has a stack-buffer overflow in
vorbis_handle_identification_packet. (CVE-2024-47538)
GStreamer has an OOB-write in convert_to_s334_1a. (CVE-2024-47539)
GStreamer uses uninitialized stack memory in Matroska/WebM demuxer.
(CVE-2024-47540)
GStreamer has an out-of-bounds write in SSA subtitle parser.
(CVE-2024-47541)
GStreamer ID3v2 parser out-of-bounds read and NULL-pointer dereference.
(CVE-2024-47542)
GStreamer has an OOB-read in qtdemux_parse_container. (CVE-2024-47543)
GStreamer has NULL-pointer dereferences in MP4/MOV demuxer CENC
handling. (CVE-2024-47544)
GStreamer has an integer underflow in FOURCC_strf parsing leading to
OOB-read. (CVE-2024-47545)
GStreamer has an integer underflow in extract_cc_from_data leading to
OOB-read. (CVE-2024-47546)
GStreamer has an OOB-read in FOURCC_SMI_ parsing. (CVE-2024-47596)
GStreamer has an OOB-read in qtdemux_parse_samples. (CVE-2024-47597)
GStreamer has an OOB-read in qtdemux_merge_sample_table.
(CVE-2024-47598)
GStreamer Insufficient error handling in JPEG decoder that can lead to
NULL-pointer dereferences. (CVE-2024-47599)
GStreamer has an OOB-read in format_channel_mask. (CVE-2024-47600)
GStreamer has a NULL-pointer dereference in Matroska/WebM demuxer.
(CVE-2024-47601)
GStreamer NULL-pointer dereferences and out-of-bounds reads in
Matroska/WebM demuxer. (CVE-2024-47602)
GStreamer NULL-pointer dereference in Matroska/WebM demuxer.
(CVE-2024-47603)
GStreamer Integer overflows in MP4/MOV demuxer and memory allocator that
can lead to out-of-bounds writes. (CVE-2024-47606)
Stack-buffer overflow in gst_opus_dec_parse_header. (CVE-2024-47607)
GStreamer has a null pointer dereference in gst_gdk_pixbuf_dec_flush.
(CVE-2024-47613)
GStreamer has an out-of-bounds write in Ogg demuxer. (CVE-2024-47615)
GStreamer has an OOB-read in gst_avi_subtitle_parse_gab2_chunk.
(CVE-2024-47774)
GStreamer has an OOB-read in parse_ds64. (CVE-2024-47775)
GStreamer has a OOB-read in gst_wavparse_cue_chunk. (CVE-2024-47776)
GStreamer has an OOB-read in gst_wavparse_smpl_chunk. (CVE-2024-47777)
GStreamer has an OOB-read in gst_wavparse_adtl_chunk. (CVE-2024-47778)
Gstreamer Use-After-Free read in Matroska CodecPrivate. (CVE-2024-47834)
Gstreamer NULL-pointer dereference in LRC subtitle parser.
(CVE-2024-47835)

Affected Software/OS:
'gstreamer1.0, gstreamer1.0-plugins-base, gstreamer1.0-plugins-good' package(s) on Mageia 9.

Solution:
Please install the updated package(s).

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2024-47537
Common Vulnerability Exposure (CVE) ID: CVE-2024-47538
Common Vulnerability Exposure (CVE) ID: CVE-2024-47539
Common Vulnerability Exposure (CVE) ID: CVE-2024-47540
Common Vulnerability Exposure (CVE) ID: CVE-2024-47541
Common Vulnerability Exposure (CVE) ID: CVE-2024-47542
Common Vulnerability Exposure (CVE) ID: CVE-2024-47543
Common Vulnerability Exposure (CVE) ID: CVE-2024-47544
Common Vulnerability Exposure (CVE) ID: CVE-2024-47545
Common Vulnerability Exposure (CVE) ID: CVE-2024-47546
Common Vulnerability Exposure (CVE) ID: CVE-2024-47596
Common Vulnerability Exposure (CVE) ID: CVE-2024-47597
Common Vulnerability Exposure (CVE) ID: CVE-2024-47598
Common Vulnerability Exposure (CVE) ID: CVE-2024-47599
Common Vulnerability Exposure (CVE) ID: CVE-2024-47600
Common Vulnerability Exposure (CVE) ID: CVE-2024-47601
Common Vulnerability Exposure (CVE) ID: CVE-2024-47602
CopyrightCopyright (C) 2025 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.