Metrics
Affected Vendors & Products
Wed, 18 Dec 2024 20:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Gstreamer Project
Gstreamer Project gstreamer |
|
CPEs | cpe:2.3:a:gstreamer_project:gstreamer:*:*:*:*:*:*:*:* | |
Vendors & Products |
Gstreamer Project
Gstreamer Project gstreamer |
|
Metrics |
cvssV3_1
|
cvssV3_1
|
Fri, 13 Dec 2024 01:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|
Wed, 11 Dec 2024 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 11 Dec 2024 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | GStreamer is a library for constructing graphs of media-handling components. An Use-After-Free read vulnerability has been discovered affecting the processing of CodecPrivate elements in Matroska streams. In the GST_MATROSKA_ID_CODECPRIVATE case within the gst_matroska_demux_parse_stream function, a data chunk is allocated using gst_ebml_read_binary. Later, the allocated memory is freed in the gst_matroska_track_free function, by the call to g_free (track->codec_priv). Finally, the freed memory is accessed in the caps_serialize function through gst_value_serialize_buffer. The freed memory will be accessed in the gst_value_serialize_buffer function. This results in a UAF read vulnerability, as the function tries to process memory that has already been freed. This vulnerability is fixed in 1.24.10. | |
Title | GHSL-2024-280: Gstreamer Use-After-Free read in Matroska CodecPrivate | |
Weaknesses | CWE-416 | |
References |
| |
Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-12-11T19:18:04.069Z
Updated: 2024-12-11T21:15:31.525Z
Reserved: 2024-10-03T14:06:12.643Z
Link: CVE-2024-47834
Updated: 2024-12-11T21:15:24.260Z
Status : Analyzed
Published: 2024-12-12T02:03:43.017
Modified: 2024-12-18T19:43:02.923
Link: CVE-2024-47834