<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">gstreamer-plugins-base-1.24.10-2.1 on GA media</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2024:14577-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2024-12-13T00:00:00Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2024-12-13T00:00:00Z</InitialReleaseDate>
    <CurrentReleaseDate>2024-12-13T00:00:00Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">gstreamer-plugins-base-1.24.10-2.1 on GA media</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">These are all security issues fixed in the gstreamer-plugins-base-1.24.10-2.1 package on the GA media of openSUSE Tumbleweed.</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">openSUSE-Tumbleweed-2024-14577</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/M64SNUMTNONUECANIAVBUNBV6RTL5TDY/</URL>
      <Description>E-Mail link for openSUSE-SU-2024:14577-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2024-47538/</URL>
      <Description>SUSE CVE CVE-2024-47538 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2024-47542/</URL>
      <Description>SUSE CVE CVE-2024-47542 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2024-47600/</URL>
      <Description>SUSE CVE CVE-2024-47600 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2024-47615/</URL>
      <Description>SUSE CVE CVE-2024-47615 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2024-47835/</URL>
      <Description>SUSE CVE CVE-2024-47835 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="openSUSE Tumbleweed">
      <Branch Type="Product Name" Name="openSUSE Tumbleweed">
        <FullProductName ProductID="openSUSE Tumbleweed" CPE="cpe:/o:opensuse:tumbleweed">openSUSE Tumbleweed</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="gstreamer-plugins-base-1.24.10-2.1">
      <FullProductName ProductID="gstreamer-plugins-base-1.24.10-2.1">gstreamer-plugins-base-1.24.10-2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="gstreamer-plugins-base-32bit-1.24.10-2.1">
      <FullProductName ProductID="gstreamer-plugins-base-32bit-1.24.10-2.1">gstreamer-plugins-base-32bit-1.24.10-2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="gstreamer-plugins-base-devel-1.24.10-2.1">
      <FullProductName ProductID="gstreamer-plugins-base-devel-1.24.10-2.1">gstreamer-plugins-base-devel-1.24.10-2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="gstreamer-plugins-base-devel-32bit-1.24.10-2.1">
      <FullProductName ProductID="gstreamer-plugins-base-devel-32bit-1.24.10-2.1">gstreamer-plugins-base-devel-32bit-1.24.10-2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="gstreamer-plugins-base-lang-1.24.10-2.1">
      <FullProductName ProductID="gstreamer-plugins-base-lang-1.24.10-2.1">gstreamer-plugins-base-lang-1.24.10-2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libgstallocators-1_0-0-1.24.10-2.1">
      <FullProductName ProductID="libgstallocators-1_0-0-1.24.10-2.1">libgstallocators-1_0-0-1.24.10-2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libgstallocators-1_0-0-32bit-1.24.10-2.1">
      <FullProductName ProductID="libgstallocators-1_0-0-32bit-1.24.10-2.1">libgstallocators-1_0-0-32bit-1.24.10-2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libgstapp-1_0-0-1.24.10-2.1">
      <FullProductName ProductID="libgstapp-1_0-0-1.24.10-2.1">libgstapp-1_0-0-1.24.10-2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libgstapp-1_0-0-32bit-1.24.10-2.1">
      <FullProductName ProductID="libgstapp-1_0-0-32bit-1.24.10-2.1">libgstapp-1_0-0-32bit-1.24.10-2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libgstaudio-1_0-0-1.24.10-2.1">
      <FullProductName ProductID="libgstaudio-1_0-0-1.24.10-2.1">libgstaudio-1_0-0-1.24.10-2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libgstaudio-1_0-0-32bit-1.24.10-2.1">
      <FullProductName ProductID="libgstaudio-1_0-0-32bit-1.24.10-2.1">libgstaudio-1_0-0-32bit-1.24.10-2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libgstfft-1_0-0-1.24.10-2.1">
      <FullProductName ProductID="libgstfft-1_0-0-1.24.10-2.1">libgstfft-1_0-0-1.24.10-2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libgstfft-1_0-0-32bit-1.24.10-2.1">
      <FullProductName ProductID="libgstfft-1_0-0-32bit-1.24.10-2.1">libgstfft-1_0-0-32bit-1.24.10-2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libgstgl-1_0-0-1.24.10-2.1">
      <FullProductName ProductID="libgstgl-1_0-0-1.24.10-2.1">libgstgl-1_0-0-1.24.10-2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libgstgl-1_0-0-32bit-1.24.10-2.1">
      <FullProductName ProductID="libgstgl-1_0-0-32bit-1.24.10-2.1">libgstgl-1_0-0-32bit-1.24.10-2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libgstpbutils-1_0-0-1.24.10-2.1">
      <FullProductName ProductID="libgstpbutils-1_0-0-1.24.10-2.1">libgstpbutils-1_0-0-1.24.10-2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libgstpbutils-1_0-0-32bit-1.24.10-2.1">
      <FullProductName ProductID="libgstpbutils-1_0-0-32bit-1.24.10-2.1">libgstpbutils-1_0-0-32bit-1.24.10-2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libgstriff-1_0-0-1.24.10-2.1">
      <FullProductName ProductID="libgstriff-1_0-0-1.24.10-2.1">libgstriff-1_0-0-1.24.10-2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libgstriff-1_0-0-32bit-1.24.10-2.1">
      <FullProductName ProductID="libgstriff-1_0-0-32bit-1.24.10-2.1">libgstriff-1_0-0-32bit-1.24.10-2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libgstrtp-1_0-0-1.24.10-2.1">
      <FullProductName ProductID="libgstrtp-1_0-0-1.24.10-2.1">libgstrtp-1_0-0-1.24.10-2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libgstrtp-1_0-0-32bit-1.24.10-2.1">
      <FullProductName ProductID="libgstrtp-1_0-0-32bit-1.24.10-2.1">libgstrtp-1_0-0-32bit-1.24.10-2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libgstrtsp-1_0-0-1.24.10-2.1">
      <FullProductName ProductID="libgstrtsp-1_0-0-1.24.10-2.1">libgstrtsp-1_0-0-1.24.10-2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libgstrtsp-1_0-0-32bit-1.24.10-2.1">
      <FullProductName ProductID="libgstrtsp-1_0-0-32bit-1.24.10-2.1">libgstrtsp-1_0-0-32bit-1.24.10-2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libgstsdp-1_0-0-1.24.10-2.1">
      <FullProductName ProductID="libgstsdp-1_0-0-1.24.10-2.1">libgstsdp-1_0-0-1.24.10-2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libgstsdp-1_0-0-32bit-1.24.10-2.1">
      <FullProductName ProductID="libgstsdp-1_0-0-32bit-1.24.10-2.1">libgstsdp-1_0-0-32bit-1.24.10-2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libgsttag-1_0-0-1.24.10-2.1">
      <FullProductName ProductID="libgsttag-1_0-0-1.24.10-2.1">libgsttag-1_0-0-1.24.10-2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libgsttag-1_0-0-32bit-1.24.10-2.1">
      <FullProductName ProductID="libgsttag-1_0-0-32bit-1.24.10-2.1">libgsttag-1_0-0-32bit-1.24.10-2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libgstvideo-1_0-0-1.24.10-2.1">
      <FullProductName ProductID="libgstvideo-1_0-0-1.24.10-2.1">libgstvideo-1_0-0-1.24.10-2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libgstvideo-1_0-0-32bit-1.24.10-2.1">
      <FullProductName ProductID="libgstvideo-1_0-0-32bit-1.24.10-2.1">libgstvideo-1_0-0-32bit-1.24.10-2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="typelib-1_0-GstAllocators-1_0-1.24.10-2.1">
      <FullProductName ProductID="typelib-1_0-GstAllocators-1_0-1.24.10-2.1">typelib-1_0-GstAllocators-1_0-1.24.10-2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="typelib-1_0-GstApp-1_0-1.24.10-2.1">
      <FullProductName ProductID="typelib-1_0-GstApp-1_0-1.24.10-2.1">typelib-1_0-GstApp-1_0-1.24.10-2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="typelib-1_0-GstAudio-1_0-1.24.10-2.1">
      <FullProductName ProductID="typelib-1_0-GstAudio-1_0-1.24.10-2.1">typelib-1_0-GstAudio-1_0-1.24.10-2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="typelib-1_0-GstGL-1_0-1.24.10-2.1">
      <FullProductName ProductID="typelib-1_0-GstGL-1_0-1.24.10-2.1">typelib-1_0-GstGL-1_0-1.24.10-2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="typelib-1_0-GstGLEGL-1_0-1.24.10-2.1">
      <FullProductName ProductID="typelib-1_0-GstGLEGL-1_0-1.24.10-2.1">typelib-1_0-GstGLEGL-1_0-1.24.10-2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="typelib-1_0-GstGLWayland-1_0-1.24.10-2.1">
      <FullProductName ProductID="typelib-1_0-GstGLWayland-1_0-1.24.10-2.1">typelib-1_0-GstGLWayland-1_0-1.24.10-2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="typelib-1_0-GstGLX11-1_0-1.24.10-2.1">
      <FullProductName ProductID="typelib-1_0-GstGLX11-1_0-1.24.10-2.1">typelib-1_0-GstGLX11-1_0-1.24.10-2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="typelib-1_0-GstPbutils-1_0-1.24.10-2.1">
      <FullProductName ProductID="typelib-1_0-GstPbutils-1_0-1.24.10-2.1">typelib-1_0-GstPbutils-1_0-1.24.10-2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="typelib-1_0-GstRtp-1_0-1.24.10-2.1">
      <FullProductName ProductID="typelib-1_0-GstRtp-1_0-1.24.10-2.1">typelib-1_0-GstRtp-1_0-1.24.10-2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="typelib-1_0-GstRtsp-1_0-1.24.10-2.1">
      <FullProductName ProductID="typelib-1_0-GstRtsp-1_0-1.24.10-2.1">typelib-1_0-GstRtsp-1_0-1.24.10-2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="typelib-1_0-GstSdp-1_0-1.24.10-2.1">
      <FullProductName ProductID="typelib-1_0-GstSdp-1_0-1.24.10-2.1">typelib-1_0-GstSdp-1_0-1.24.10-2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="typelib-1_0-GstTag-1_0-1.24.10-2.1">
      <FullProductName ProductID="typelib-1_0-GstTag-1_0-1.24.10-2.1">typelib-1_0-GstTag-1_0-1.24.10-2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="typelib-1_0-GstVideo-1_0-1.24.10-2.1">
      <FullProductName ProductID="typelib-1_0-GstVideo-1_0-1.24.10-2.1">typelib-1_0-GstVideo-1_0-1.24.10-2.1</FullProductName>
    </Branch>
    <Relationship ProductReference="gstreamer-plugins-base-1.24.10-2.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:gstreamer-plugins-base-1.24.10-2.1">gstreamer-plugins-base-1.24.10-2.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="gstreamer-plugins-base-32bit-1.24.10-2.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:gstreamer-plugins-base-32bit-1.24.10-2.1">gstreamer-plugins-base-32bit-1.24.10-2.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="gstreamer-plugins-base-devel-1.24.10-2.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:gstreamer-plugins-base-devel-1.24.10-2.1">gstreamer-plugins-base-devel-1.24.10-2.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="gstreamer-plugins-base-devel-32bit-1.24.10-2.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:gstreamer-plugins-base-devel-32bit-1.24.10-2.1">gstreamer-plugins-base-devel-32bit-1.24.10-2.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="gstreamer-plugins-base-lang-1.24.10-2.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:gstreamer-plugins-base-lang-1.24.10-2.1">gstreamer-plugins-base-lang-1.24.10-2.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgstallocators-1_0-0-1.24.10-2.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libgstallocators-1_0-0-1.24.10-2.1">libgstallocators-1_0-0-1.24.10-2.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgstallocators-1_0-0-32bit-1.24.10-2.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libgstallocators-1_0-0-32bit-1.24.10-2.1">libgstallocators-1_0-0-32bit-1.24.10-2.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgstapp-1_0-0-1.24.10-2.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libgstapp-1_0-0-1.24.10-2.1">libgstapp-1_0-0-1.24.10-2.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgstapp-1_0-0-32bit-1.24.10-2.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libgstapp-1_0-0-32bit-1.24.10-2.1">libgstapp-1_0-0-32bit-1.24.10-2.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgstaudio-1_0-0-1.24.10-2.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libgstaudio-1_0-0-1.24.10-2.1">libgstaudio-1_0-0-1.24.10-2.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgstaudio-1_0-0-32bit-1.24.10-2.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libgstaudio-1_0-0-32bit-1.24.10-2.1">libgstaudio-1_0-0-32bit-1.24.10-2.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgstfft-1_0-0-1.24.10-2.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libgstfft-1_0-0-1.24.10-2.1">libgstfft-1_0-0-1.24.10-2.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgstfft-1_0-0-32bit-1.24.10-2.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libgstfft-1_0-0-32bit-1.24.10-2.1">libgstfft-1_0-0-32bit-1.24.10-2.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgstgl-1_0-0-1.24.10-2.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libgstgl-1_0-0-1.24.10-2.1">libgstgl-1_0-0-1.24.10-2.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgstgl-1_0-0-32bit-1.24.10-2.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libgstgl-1_0-0-32bit-1.24.10-2.1">libgstgl-1_0-0-32bit-1.24.10-2.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgstpbutils-1_0-0-1.24.10-2.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libgstpbutils-1_0-0-1.24.10-2.1">libgstpbutils-1_0-0-1.24.10-2.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgstpbutils-1_0-0-32bit-1.24.10-2.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libgstpbutils-1_0-0-32bit-1.24.10-2.1">libgstpbutils-1_0-0-32bit-1.24.10-2.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgstriff-1_0-0-1.24.10-2.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libgstriff-1_0-0-1.24.10-2.1">libgstriff-1_0-0-1.24.10-2.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgstriff-1_0-0-32bit-1.24.10-2.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libgstriff-1_0-0-32bit-1.24.10-2.1">libgstriff-1_0-0-32bit-1.24.10-2.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgstrtp-1_0-0-1.24.10-2.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libgstrtp-1_0-0-1.24.10-2.1">libgstrtp-1_0-0-1.24.10-2.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgstrtp-1_0-0-32bit-1.24.10-2.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libgstrtp-1_0-0-32bit-1.24.10-2.1">libgstrtp-1_0-0-32bit-1.24.10-2.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgstrtsp-1_0-0-1.24.10-2.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libgstrtsp-1_0-0-1.24.10-2.1">libgstrtsp-1_0-0-1.24.10-2.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgstrtsp-1_0-0-32bit-1.24.10-2.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libgstrtsp-1_0-0-32bit-1.24.10-2.1">libgstrtsp-1_0-0-32bit-1.24.10-2.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgstsdp-1_0-0-1.24.10-2.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libgstsdp-1_0-0-1.24.10-2.1">libgstsdp-1_0-0-1.24.10-2.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgstsdp-1_0-0-32bit-1.24.10-2.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libgstsdp-1_0-0-32bit-1.24.10-2.1">libgstsdp-1_0-0-32bit-1.24.10-2.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgsttag-1_0-0-1.24.10-2.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libgsttag-1_0-0-1.24.10-2.1">libgsttag-1_0-0-1.24.10-2.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgsttag-1_0-0-32bit-1.24.10-2.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libgsttag-1_0-0-32bit-1.24.10-2.1">libgsttag-1_0-0-32bit-1.24.10-2.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgstvideo-1_0-0-1.24.10-2.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libgstvideo-1_0-0-1.24.10-2.1">libgstvideo-1_0-0-1.24.10-2.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgstvideo-1_0-0-32bit-1.24.10-2.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libgstvideo-1_0-0-32bit-1.24.10-2.1">libgstvideo-1_0-0-32bit-1.24.10-2.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="typelib-1_0-GstAllocators-1_0-1.24.10-2.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:typelib-1_0-GstAllocators-1_0-1.24.10-2.1">typelib-1_0-GstAllocators-1_0-1.24.10-2.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="typelib-1_0-GstApp-1_0-1.24.10-2.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:typelib-1_0-GstApp-1_0-1.24.10-2.1">typelib-1_0-GstApp-1_0-1.24.10-2.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="typelib-1_0-GstAudio-1_0-1.24.10-2.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:typelib-1_0-GstAudio-1_0-1.24.10-2.1">typelib-1_0-GstAudio-1_0-1.24.10-2.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="typelib-1_0-GstGL-1_0-1.24.10-2.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:typelib-1_0-GstGL-1_0-1.24.10-2.1">typelib-1_0-GstGL-1_0-1.24.10-2.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="typelib-1_0-GstGLEGL-1_0-1.24.10-2.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:typelib-1_0-GstGLEGL-1_0-1.24.10-2.1">typelib-1_0-GstGLEGL-1_0-1.24.10-2.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="typelib-1_0-GstGLWayland-1_0-1.24.10-2.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:typelib-1_0-GstGLWayland-1_0-1.24.10-2.1">typelib-1_0-GstGLWayland-1_0-1.24.10-2.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="typelib-1_0-GstGLX11-1_0-1.24.10-2.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:typelib-1_0-GstGLX11-1_0-1.24.10-2.1">typelib-1_0-GstGLX11-1_0-1.24.10-2.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="typelib-1_0-GstPbutils-1_0-1.24.10-2.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:typelib-1_0-GstPbutils-1_0-1.24.10-2.1">typelib-1_0-GstPbutils-1_0-1.24.10-2.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="typelib-1_0-GstRtp-1_0-1.24.10-2.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:typelib-1_0-GstRtp-1_0-1.24.10-2.1">typelib-1_0-GstRtp-1_0-1.24.10-2.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="typelib-1_0-GstRtsp-1_0-1.24.10-2.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:typelib-1_0-GstRtsp-1_0-1.24.10-2.1">typelib-1_0-GstRtsp-1_0-1.24.10-2.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="typelib-1_0-GstSdp-1_0-1.24.10-2.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:typelib-1_0-GstSdp-1_0-1.24.10-2.1">typelib-1_0-GstSdp-1_0-1.24.10-2.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="typelib-1_0-GstTag-1_0-1.24.10-2.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:typelib-1_0-GstTag-1_0-1.24.10-2.1">typelib-1_0-GstTag-1_0-1.24.10-2.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="typelib-1_0-GstVideo-1_0-1.24.10-2.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:typelib-1_0-GstVideo-1_0-1.24.10-2.1">typelib-1_0-GstVideo-1_0-1.24.10-2.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">GStreamer is a library for constructing graphs of media-handling components. A stack-buffer overflow has been detected in the `vorbis_handle_identification_packet` function within `gstvorbisdec.c`. The position array is a stack-allocated buffer of size 64. If vd-&gt;vi.channels exceeds 64, the for loop will write beyond the boundaries of the position array. The value written will always be `GST_AUDIO_CHANNEL_POSITION_NONE`. This vulnerability allows someone to overwrite the EIP address allocated in the stack. Additionally, this bug can overwrite the `GstAudioInfo` info structure. This vulnerability is fixed in 1.24.10.</Note>
    </Notes>
    <CVE>CVE-2024-47538</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:gstreamer-plugins-base-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:gstreamer-plugins-base-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:gstreamer-plugins-base-devel-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:gstreamer-plugins-base-devel-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:gstreamer-plugins-base-lang-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstallocators-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstallocators-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstapp-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstapp-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstaudio-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstaudio-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstfft-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstfft-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstgl-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstgl-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstpbutils-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstpbutils-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstriff-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstriff-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstrtp-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstrtp-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstrtsp-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstrtsp-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstsdp-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstsdp-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgsttag-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgsttag-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstvideo-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstvideo-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstAllocators-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstApp-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstAudio-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstGL-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstGLEGL-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstGLWayland-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstGLX11-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstPbutils-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstRtp-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstRtsp-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstSdp-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstTag-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstVideo-1_0-1.24.10-2.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/M64SNUMTNONUECANIAVBUNBV6RTL5TDY/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2024-47538.html</URL>
        <Description>CVE-2024-47538</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1234415</URL>
        <Description>SUSE Bug 1234415</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference has been discovered in the id3v2_read_synch_uint function, located in id3v2.c. If id3v2_read_synch_uint is called with a null work-&gt;hdr.frame_data, the pointer guint8 *data is accessed without validation, resulting in a null pointer dereference. This vulnerability can result in a Denial of Service (DoS) by triggering a segmentation fault (SEGV). This vulnerability is fixed in 1.24.10.</Note>
    </Notes>
    <CVE>CVE-2024-47542</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:gstreamer-plugins-base-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:gstreamer-plugins-base-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:gstreamer-plugins-base-devel-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:gstreamer-plugins-base-devel-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:gstreamer-plugins-base-lang-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstallocators-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstallocators-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstapp-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstapp-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstaudio-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstaudio-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstfft-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstfft-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstgl-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstgl-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstpbutils-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstpbutils-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstriff-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstriff-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstrtp-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstrtp-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstrtsp-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstrtsp-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstsdp-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstsdp-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgsttag-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgsttag-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstvideo-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstvideo-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstAllocators-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstApp-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstAudio-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstGL-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstGLEGL-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstGLWayland-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstGLX11-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstPbutils-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstRtp-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstRtsp-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstSdp-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstTag-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstVideo-1_0-1.24.10-2.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/M64SNUMTNONUECANIAVBUNBV6RTL5TDY/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2024-47542.html</URL>
        <Description>CVE-2024-47542</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1234460</URL>
        <Description>SUSE Bug 1234460</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been detected in the format_channel_mask function in gst-discoverer.c. The vulnerability affects the local array position, which is defined with a fixed size of 64 elements. However, the function gst_discoverer_audio_info_get_channels may return a guint channels value greater than 64. This causes the for loop to attempt access beyond the bounds of the position array, resulting in an OOB-read when an index greater than 63 is used. This vulnerability can result in reading unintended bytes from the stack. Additionally, the dereference of value-&gt;value_nick after the OOB-read can lead to further memory corruption or undefined behavior. This vulnerability is fixed in 1.24.10.</Note>
    </Notes>
    <CVE>CVE-2024-47600</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:gstreamer-plugins-base-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:gstreamer-plugins-base-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:gstreamer-plugins-base-devel-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:gstreamer-plugins-base-devel-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:gstreamer-plugins-base-lang-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstallocators-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstallocators-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstapp-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstapp-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstaudio-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstaudio-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstfft-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstfft-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstgl-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstgl-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstpbutils-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstpbutils-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstriff-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstriff-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstrtp-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstrtp-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstrtsp-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstrtsp-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstsdp-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstsdp-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgsttag-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgsttag-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstvideo-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstvideo-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstAllocators-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstApp-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstAudio-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstGL-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstGLEGL-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstGLWayland-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstGLX11-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstPbutils-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstRtp-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstRtsp-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstSdp-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstTag-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstVideo-1_0-1.24.10-2.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/M64SNUMTNONUECANIAVBUNBV6RTL5TDY/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2024-47600.html</URL>
        <Description>CVE-2024-47600</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1234453</URL>
        <Description>SUSE Bug 1234453</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">GStreamer is a library for constructing graphs of media-handling components. An OOB-Write has been detected in the function gst_parse_vorbis_setup_packet within vorbis_parse.c. The integer size is read from the input file without proper validation. As a result, size can exceed the fixed size of the pad-&gt;vorbis_mode_sizes array (which size is 256). When this happens, the for loop overwrites the entire pad structure with 0s and 1s, affecting adjacent memory as well. This OOB-write can overwrite up to 380 bytes of memory beyond the boundaries of the pad-&gt;vorbis_mode_sizes array. This vulnerability is fixed in 1.24.10.</Note>
    </Notes>
    <CVE>CVE-2024-47615</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:gstreamer-plugins-base-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:gstreamer-plugins-base-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:gstreamer-plugins-base-devel-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:gstreamer-plugins-base-devel-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:gstreamer-plugins-base-lang-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstallocators-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstallocators-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstapp-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstapp-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstaudio-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstaudio-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstfft-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstfft-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstgl-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstgl-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstpbutils-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstpbutils-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstriff-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstriff-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstrtp-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstrtp-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstrtsp-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstrtsp-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstsdp-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstsdp-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgsttag-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgsttag-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstvideo-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstvideo-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstAllocators-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstApp-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstAudio-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstGL-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstGLEGL-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstGLWayland-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstGLX11-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstPbutils-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstRtp-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstRtsp-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstSdp-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstTag-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstVideo-1_0-1.24.10-2.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/M64SNUMTNONUECANIAVBUNBV6RTL5TDY/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2024-47615.html</URL>
        <Description>CVE-2024-47615</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1234456</URL>
        <Description>SUSE Bug 1234456</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been detected in the parse_lrc function within gstsubparse.c. The parse_lrc function calls strchr() to find the character ']' in the string line. The pointer returned by this call is then passed to g_strdup(). However, if the string line does not contain the character ']', strchr() returns NULL, and a call to g_strdup(start + 1) leads to a null pointer dereference. This vulnerability is fixed in 1.24.10.</Note>
    </Notes>
    <CVE>CVE-2024-47835</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:gstreamer-plugins-base-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:gstreamer-plugins-base-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:gstreamer-plugins-base-devel-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:gstreamer-plugins-base-devel-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:gstreamer-plugins-base-lang-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstallocators-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstallocators-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstapp-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstapp-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstaudio-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstaudio-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstfft-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstfft-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstgl-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstgl-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstpbutils-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstpbutils-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstriff-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstriff-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstrtp-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstrtp-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstrtsp-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstrtsp-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstsdp-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstsdp-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgsttag-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgsttag-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstvideo-1_0-0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libgstvideo-1_0-0-32bit-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstAllocators-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstApp-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstAudio-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstGL-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstGLEGL-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstGLWayland-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstGLX11-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstPbutils-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstRtp-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstRtsp-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstSdp-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstTag-1_0-1.24.10-2.1</ProductID>
        <ProductID>openSUSE Tumbleweed:typelib-1_0-GstVideo-1_0-1.24.10-2.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/M64SNUMTNONUECANIAVBUNBV6RTL5TDY/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2024-47835.html</URL>
        <Description>CVE-2024-47835</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1234450</URL>
        <Description>SUSE Bug 1234450</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
