Metrics
Affected Vendors & Products
| Source | ID | Title | 
|---|---|---|
  Debian DLA | 
                DLA-4071-1 | gst-plugins-good1.0 security update | 
  Debian DSA | 
                DSA-5838-1 | gst-plugins-good1.0 security update | 
  EUVD | 
                EUVD-2024-42820 | GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been discovered in the gst_matroska_demux_parse_blockgroup_or_simpleblock function within matroska-demux.c. This function does not properly check the validity of the GstBuffer *sub pointer before performing dereferences. As a result, null pointer dereferences may occur. This vulnerability is fixed in 1.24.10. | 
  Ubuntu USN | 
                USN-7176-1 | GStreamer Good Plugins vulnerabilities | 
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 03 Nov 2025 21:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
         | 
Wed, 14 May 2025 02:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Redhat
         Redhat enterprise Linux  | 
|
| CPEs | cpe:/a:redhat:enterprise_linux:9 | |
| Vendors & Products | 
        
        Redhat
         Redhat enterprise Linux  | 
Wed, 18 Dec 2024 22:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Gstreamer Project
         Gstreamer Project gstreamer  | 
|
| CPEs | cpe:2.3:a:gstreamer_project:gstreamer:*:*:*:*:*:*:*:* | |
| Vendors & Products | 
        
        Gstreamer Project
         Gstreamer Project gstreamer  | 
|
| Metrics | 
        
        
        cvssV3_1
         
  | 
    
        
        
        cvssV3_1
         
  | 
Fri, 13 Dec 2024 01:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
         | |
| Metrics | 
        
        
        threat_severity
         
  | 
    
        
        cvssV3_1
         
 
  | 
Thu, 12 Dec 2024 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Wed, 11 Dec 2024 19:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been discovered in the gst_matroska_demux_parse_blockgroup_or_simpleblock function within matroska-demux.c. This function does not properly check the validity of the GstBuffer *sub pointer before performing dereferences. As a result, null pointer dereferences may occur. This vulnerability is fixed in 1.24.10. | |
| Title | GHSL-2024-249: GStreamer has a NULL-pointer dereference in Matroska/WebM demuxer | |
| Weaknesses | CWE-476 | |
| References | 
         | |
| Metrics | 
        
        cvssV4_0
         
  | 
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-11-03T20:39:50.359Z
Reserved: 2024-09-27T20:37:22.119Z
Link: CVE-2024-47601
Updated: 2024-12-12T14:26:03.110Z
Status : Modified
Published: 2024-12-12T02:03:31.727
Modified: 2025-11-03T21:16:24.573
Link: CVE-2024-47601
                        OpenCVE Enrichment
                    No data.
 Debian DLA
 Debian DSA
 EUVD
 Ubuntu USN