CVE Vulnerabilities

CVE-2024-47546

Integer Underflow (Wrap or Wraparound)

Published: Dec 12, 2024 | Modified: Dec 18, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
6.2 MODERATE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

GStreamer is a library for constructing graphs of media-handling components. An integer underflow has been detected in extract_cc_from_data function within qtdemux.c. In the FOURCC_c708 case, the subtraction atom_length - 8 may result in an underflow if atom_length is less than 8. When that subtraction underflows, *cclen ends up being a large number, and then cclen is passed to g_memdup2 leading to an out-of-bounds (OOB) read. This vulnerability is fixed in 1.24.10.

Weakness

The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

Affected Software

Name Vendor Start Version End Version
Gstreamer Gstreamer_project * 1.24.10 (excluding)
Gst-plugins-good1.0 Ubuntu focal *
Gst-plugins-good1.0 Ubuntu jammy *
Gst-plugins-good1.0 Ubuntu noble *
Gst-plugins-good1.0 Ubuntu oracular *
Gst-plugins-good1.0 Ubuntu upstream *

References