Name
CVE-2024-47774
Description
GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been identified in the gst_avi_subtitle_parse_gab2_chunk function within gstavisubtitle.c. The function reads the name_length value directly from the input file without checking it properly. Then, the a condition, does not properly handle cases where name_length is greater than 0xFFFFFFFF - 17, causing an integer overflow. In such scenario, the function attempts to access memory beyond the buffer leading to an OOB-read. This vulnerability is fixed in 1.24.10.
CWEs
Published Date
Updated Date
Workaround
-
Analysis#
Vulnerability Ratings#
5.1
CVSSv4
9.1
CVSSv31
NaN
other
Others affected components#
Name
Project
Project Version
Version
Status
buildroot
2025.02.x
1.24.13
Not Affected
buildroot
master
1.24.13
Not Affected
openwrt
master
1.26.4-r2
Not Affected
openwrt
openwrt-25.12
1.26.4-r2
Not Affected
yocto
kirkstone
1.20.7
Not Affected
yocto
kirkstone
1.20.7
Patched
yocto
master
1.28.4
Not Affected
yocto
master
1.28.4
Not Affected
Resolved with patches#
gstreamer1.0-plugins-good (yocto:kirkstone)
#
Title
Author
Resolve
1
avisubtitle: Fix size checks and avoid overflows when
=?UTF-8?q?Sebastian=20Dr=C3=B6ge?= <sebastian@centricular.com>
CVE-2024-47774
gstreamer1.0-plugins-good (yocto:scarthgap)
#
Title
Author
Resolve
1
avisubtitle: Fix size checks and avoid overflows when
=?UTF-8?q?Sebastian=20Dr=C3=B6ge?= <sebastian@centricular.com>
CVE-2024-47774