CVE-2024-47539
CVSS V2 None
CVSS V3 None
Description
GStreamer is a library for constructing graphs of media-handling components. An out-of-bounds write vulnerability was identified in the convert_to_s334_1a function in isomp4/qtdemux.c. The vulnerability arises due to a discrepancy between the size of memory allocated to the storage array and the loop condition i * 2 < ccpair_size. Specifically, when ccpair_size is even, the allocated size in storage does not match the loop's expected bounds, resulting in an out-of-bounds write. This bug allows for the overwriting of up to 3 bytes beyond the allocated bounds of the storage array. This vulnerability is fixed in 1.24.10.
Overview
- CVE ID
- CVE-2024-47539
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-12-11T18:53:00.750Z
- Last Modified Date
- 2024-12-11T21:41:10.528Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://securitylab.github.com/advisories/GHSL-2024-195_Gstreamer/ | x_refsource_CONFIRM |
https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/8059.patch | x_refsource_MISC |
https://gstreamer.freedesktop.org/security/sa-2024-0007.html | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-47539 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-47539 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-12-12 13:22:17 | Added to TrackCVE |