Out of Bounds Read in GStreamer Library Affecting Multiple Media Applications
CVE-2024-47598

5.1MEDIUM

Key Information:

Vendor

Gstreamer

Status
Vendor
CVE Published:
12 December 2024

What is CVE-2024-47598?

An Out of Bounds (OOB) read vulnerability has been detected in the GStreamer library, specifically within the qtdemux_merge_sample_table function in qtdemux.c. This vulnerability arises due to inadequate validation of the stts buffer size before accessing stts_duration. As a result, the program may inadvertently read 4 bytes beyond the allocated memory limits of the stts array, potentially exposing sensitive information or causing undefined behavior in applications leveraging GStreamer. The issue has been addressed in version 1.24.10 of GStreamer.

Affected Version(s)

gstreamer < 1.24.10

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

.