## This update for gstreamer-plugins-good fixes the following issues: * CVE-2024-47530: Fixed an uninitialized stack memory in Matroska/WebM demuxer. (boo#1234421) * CVE-2024-47537: Fixed an out-of-bounds write in isomp4/qtdemux.c. (boo#1234414) * CVE-2024-47543: Fixed an out-of-bounds write in qtdemux_parse_container. (boo#1234462) * CVE-2024-47544: Fixed a NULL-pointer dereferences in MP4/MOV demuxer CENC handling. (boo#1234473) * CVE-2024-47545: Fixed an integer underflow in FOURCC_strf parsing leading to out-of-bounds read. (boo#1234476) * CVE-2024-47596: Fixed an integer underflow in MP4/MOV demuxer that can lead to out-of-bounds reads. (boo#1234424) * CVE-2024-47597: Fixed an out-of-bounds reads in MP4/MOV demuxer sample table parser (boo#1234425)
* bsc#1234414
* bsc#1234421
* bsc#1234424
* bsc#1234425
* bsc#1234427
* bsc#1234428
* bsc#1234432
* bsc#1234433
* bsc#1234434
* bsc#1234435
* bsc#1234436
* bsc#1234439
* bsc#1234440
* bsc#1234446
* bsc#1234447
* bsc#1234449
* bsc#1234462
* bsc#1234473
* bsc#1234476
Cross-
* CVE-2024-47530
* CVE-2024-47537
* CVE-2024-47543
* CVE-2024-47544
* CVE-2024-47545
* CVE-2024-47596
* CVE-2024-47597
* CVE-2024-47599
* CVE-2024-47601
* CVE-2024-47602
* CVE-2024-47603
* CVE-2024-47606
* CVE-2024-47613
* CVE-2024-47774
* CVE-2024-47775
* CVE-2024-47776
* CVE-2024-47777
* CVE-2024-47778
* CVE-2024-47834
CVSS scores:
* CVE-2024-47530 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
* CVE-2024-47530 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Get the latest Linux and open source security news straight to your inbox.