Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments.
Metrics
Affected Vendors & Products
References
History
Fri, 06 Sep 2024 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Redhat rhel Tus
|
|
CPEs | cpe:/a:redhat:enterprise_linux:9 cpe:/a:redhat:rhel_aus:8.4 cpe:/a:redhat:rhel_e4s:8.4 cpe:/a:redhat:rhel_tus:8.4 |
|
Vendors & Products |
Redhat rhel Tus
|
Tue, 27 Aug 2024 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Redhat rhel Aus
|
|
CPEs | cpe:/a:redhat:rhel_aus:8.2 | |
Vendors & Products |
Redhat rhel Aus
|
Tue, 27 Aug 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Gstreamer
Gstreamer orc |
|
Weaknesses | CWE-787 | |
CPEs | cpe:2.3:a:gstreamer:orc:*:*:*:*:*:*:*:* | |
Vendors & Products |
Gstreamer
Gstreamer orc |
|
Metrics |
cvssV3_1
|
cvssV3_1
|
Tue, 20 Aug 2024 22:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Redhat rhel E4s
Redhat rhel Eus |
|
CPEs | cpe:/a:redhat:rhel_e4s:9.0 cpe:/a:redhat:rhel_eus:9.2 |
|
Vendors & Products |
Redhat rhel E4s
Redhat rhel Eus |
Fri, 16 Aug 2024 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Redhat
Redhat enterprise Linux |
|
CPEs | cpe:/a:redhat:enterprise_linux:8 | |
Vendors & Products |
Redhat
Redhat enterprise Linux |
MITRE
Status: PUBLISHED
Assigner: jpcert
Published: 2024-07-26T06:03:23.768Z
Updated: 2024-08-02T04:39:54.855Z
Reserved: 2024-07-12T07:12:22.373Z
Link: CVE-2024-40897
Vulnrichment
Updated: 2024-08-02T04:39:54.855Z
NVD
Status : Modified
Published: 2024-07-26T06:15:02.290
Modified: 2024-11-21T09:31:48.450
Link: CVE-2024-40897
Redhat