CVE-2024-47607

CVSS V2 None CVSS V3 None
Description
GStreamer is a library for constructing graphs of media-handling components. stack-buffer overflow has been detected in the gst_opus_dec_parse_header function within `gstopusdec.c'. The pos array is a stack-allocated buffer of size 64. If n_channels exceeds 64, the for loop will write beyond the boundaries of the pos array. The value written will always be GST_AUDIO_CHANNEL_POSITION_NONE. This bug allows to overwrite the EIP address allocated in the stack. This vulnerability is fixed in 1.24.10.
Overview
  • CVE ID
  • CVE-2024-47607
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-12-11T19:13:27.569Z
  • Last Modified Date
  • 2024-12-11T19:13:27.569Z
History
Created Old Value New Value Data Type Notes
2024-12-12 13:24:32 Added to TrackCVE