GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been discovered in the gst_jpeg_dec_negotiate function in gstjpegdec.c. This function does not check for a NULL return value from gst_video_decoder_set_output_state. When this happens, dereferences of the outstate pointer will lead to a null pointer dereference. This vulnerability can result in a Denial of Service (DoS) by triggering a segmentation fault (SEGV). This vulnerability is fixed in 1.24.10.
| Version | Score | Severity | Vector String |
|---|---|---|---|
| 4.0 | 6.8 | Medium | CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
| Product | Vendor | Version |
|---|---|---|
| gstreamer | gstreamer | 2.1.0 |
| gstreamer | gstreamer | < 7393c681f9aa05ffe2385e8716989565eed2fe06 |