[Japanese] | |
JVNDB-2024-000075 | |
ORC vulnerable to stack-based buffer overflow | |
Overview | |
ORC provided by GStreamer is typically used when developing GStreamer plugins. Stack-based buffer overflow vulnerability (CWE-121) exists in orcparse.c of ORC. | |
CVSS Severity (What is CVSS?) | |
CVSS V3 Severity:
Base Metrics 7.0 (High) [IPA Score]
| |
Affected Products | |
| |
GStreamer | |
| |
Impact | |
If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments. | |
Solution | |
[Update the Software] | |
Vendor Information | |
GStreamer | |
CWE (What is CWE?) | |
| |
CVE (What is CVE?) | |
| |
References | |
| |
Revision History | |
|
Date Public | 2024/07/26 |
Date First Published | 2024/07/26 |
Date Last Updated | 2024/07/26 |