CVE-2024-47543
GHSL-2024-236: GStreamer has an OOB-read in qtdemux_parse_container
Published:
12/11/2024
Last updated:
12/12/2024
Reserved:
9/25/2024
GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been discovered in qtdemux_parse_container function within qtdemux.c. In the parent function qtdemux_parse_node, the value of length is not well checked. So, if length is big enough, it causes the pointer end to point beyond the boundaries of buffer. Subsequently, in the qtdemux_parse_container function, the while loop can trigger an OOB-read, accessing memory beyond the bounds of buf. This vulnerability can result in reading up to 4GB of process memory or potentially causing a segmentation fault (SEGV) when accessing invalid memory. This vulnerability is fixed in 1.24.10.
CNA assigner:
GitHub_M (a0819718-46f1-4df5-94e2-005712e83aaa)
Requested by:
n/a
Products affected (1)
Product |
Vendor |
Version |
gstreamer |
gstreamer
|
n/a
|