CVE-2024-47777

GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been identified in the gst_wavparse_smpl_chunk function within gstwavparse.c. This function attempts to read 4 bytes from the data + 12 offset without checking if the size of the data buffer is sufficient. If the buffer is too small, the function reads beyond its bounds. This vulnerability may result in reading 4 bytes out of the boundaries of the data buffer. This vulnerability is fixed in 1.24.10.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gstreamer_project:gstreamer:*:*:*:*:*:*:*:*

History

18 Dec 2024, 19:40

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
First Time Gstreamer Project gstreamer
Gstreamer Project
CPE cpe:2.3:a:gstreamer_project:gstreamer:*:*:*:*:*:*:*:*
References () https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/8042.patch - () https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/8042.patch - Patch
References () https://gstreamer.freedesktop.org/security/sa-2024-0027.html - () https://gstreamer.freedesktop.org/security/sa-2024-0027.html - Release Notes
References () https://securitylab.github.com/advisories/GHSL-2024-259_Gstreamer/ - () https://securitylab.github.com/advisories/GHSL-2024-259_Gstreamer/ - Third Party Advisory
Summary
  • (es) GStreamer es una librería para construir gráficos de componentes de manejo de medios. Se ha identificado una vulnerabilidad de lectura OOB en la función gst_wavparse_smpl_chunk dentro de gstwavparse.c. Esta función intenta leer 4 bytes del desplazamiento de datos + 12 sin verificar si el tamaño del búfer de datos es suficiente. Si el búfer es demasiado pequeño, la función lee más allá de sus límites. Esta vulnerabilidad puede resultar en la lectura de 4 bytes fuera de los límites del búfer de datos. Esta vulnerabilidad se corrigió en 1.24.10.

12 Dec 2024, 02:03

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-12 02:03

Updated : 2024-12-18 19:40


NVD link : CVE-2024-47777

Mitre link : CVE-2024-47777

CVE.ORG link : CVE-2024-47777


JSON object : View

Products Affected

gstreamer_project

  • gstreamer
CWE
CWE-125

Out-of-bounds Read