CVE-2024-47775

GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been found in the parse_ds64 function within gstwavparse.c. The parse_ds64 function does not check that the buffer buf contains sufficient data before attempting to read from it, doing multiple GST_READ_UINT32_LE operations without performing boundary checks. This can lead to an OOB-read when buf is smaller than expected. This vulnerability allows reading beyond the bounds of the data buffer, potentially leading to a crash (denial of service) or the leak of sensitive data. This vulnerability is fixed in 1.24.10.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gstreamer_project:gstreamer:*:*:*:*:*:*:*:*

History

18 Dec 2024, 21:37

Type Values Removed Values Added
Summary
  • (es) GStreamer es una librería para construir gráficos de componentes de manejo de medios. Se ha encontrado una vulnerabilidad de lectura OOB en la función parse_ds64 dentro de gstwavparse.c. La función parse_ds64 no verifica que el búfer buf contenga datos suficientes antes de intentar leer de él, y realiza múltiples operaciones GST_READ_UINT32_LE sin realizar verificaciones de los límites. Esto puede provocar una lectura OOB cuando buf es más pequeño de lo esperado. Esta vulnerabilidad permite leer más allá de los límites del búfer de datos, lo que puede provocar un bloqueo (denegación de servicio) o la fuga de datos confidenciales. Esta vulnerabilidad se corrigió en la versión 1.24.10.
References () https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/8042.patch - () https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/8042.patch - Patch
References () https://gstreamer.freedesktop.org/security/sa-2024-0027.html - () https://gstreamer.freedesktop.org/security/sa-2024-0027.html - Release Notes
References () https://securitylab.github.com/advisories/GHSL-2024-261_Gstreamer/ - () https://securitylab.github.com/advisories/GHSL-2024-261_Gstreamer/ - Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
CPE cpe:2.3:a:gstreamer_project:gstreamer:*:*:*:*:*:*:*:*
First Time Gstreamer Project gstreamer
Gstreamer Project

12 Dec 2024, 02:03

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-12 02:03

Updated : 2024-12-18 21:37


NVD link : CVE-2024-47775

Mitre link : CVE-2024-47775

CVE.ORG link : CVE-2024-47775


JSON object : View

Products Affected

gstreamer_project

  • gstreamer
CWE
CWE-125

Out-of-bounds Read