[WID-SEC-2024-1209] GStreamer: Schwachstelle ermöglicht Codeausführung CVSS Base Score 7.8 (hoch) CVSS Temporal Score 6.8 (mittel) Remoteangriff nein Datum 21.05.2024 Stand UPDATE 12.08.2026 Mitigation ja Betroffene Systeme Betriebssystem Linux Windows Produktbeschreibung GStreamer ist ein Multimedia-Framework mit einer Plugin-basierten Architektur für eine Vielzahl von Plattformen. Produkte UPDATE 05.10.2025 RESF Rocky Linux UPDATE 11.11.2024 Oracle Linux UPDATE 10.11.2024 Red Hat Enterprise Linux UPDATE 22.07.2024 Amazon Linux 2 UPDATE 30.05.2024 Debian Linux Ubuntu Linux SUSE Linux 21.05.2024 Open Source GStreamer Angriff Angriff Ein entfernter, anonymer Angreifer kann eine Schwachstelle in GStreamer ausnutzen, um beliebigen Programmcode auszuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben
A vulnerability in GStreamer (CVE not provided) allows an attacker to execute arbitrary code, though it does not require remote access. The CVSS Base Score is 7.8 (High). The article lists numerous affected Linux distributions but does not provide specific GStreamer version ranges or a fixed version number to upgrade to.