CVE-2024-47596

CVSS V2 None CVSS V3 None
Description
GStreamer is a library for constructing graphs of media-handling components. An OOB-read has been discovered in the qtdemux_parse_svq3_stsd_data function within qtdemux.c. In the FOURCC_SMI_ case, seqh_size is read from the input file without proper validation. If seqh_size is greater than the remaining size of the data buffer, it can lead to an OOB-read in the following call to gst_buffer_fill, which internally uses memcpy. This vulnerability can result in reading up to 4GB of process memory or potentially causing a segmentation fault (SEGV) when accessing invalid memory. This vulnerability is fixed in 1.24.10.
Overview
  • CVE ID
  • CVE-2024-47596
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-12-11T19:01:23.353Z
  • Last Modified Date
  • 2024-12-11T19:01:23.353Z
History
Created Old Value New Value Data Type Notes
2024-12-12 13:22:52 Added to TrackCVE