Name
CVE-2024-47776
Description
GStreamer is a library for constructing graphs of media-handling components. An OOB-read has been discovered in gst_wavparse_cue_chunk within gstwavparse.c. The vulnerability happens due to a discrepancy between the size of the data buffer and the size value provided to the function. This mismatch causes the comparison if (size < 4 + ncues * 24) to fail in some cases, allowing the subsequent loop to access beyond the bounds of the data buffer. The root cause of this discrepancy stems from a miscalculation when clipping the chunk size based on upstream data size. This vulnerability allows reading beyond the bounds of the data buffer, potentially leading to a crash (denial of service) or the leak of sensitive data. This vulnerability is fixed in 1.24.10.
CWEs
Published Date
Updated Date
Workaround
-
Analysis#
Vulnerability Ratings#
5.1
CVSSv4
9.1
CVSSv31
NaN
other
Others affected components#
Name
Project
Project Version
Version
Status
buildroot
2025.02.x
1.24.13
Not Affected
buildroot
master
1.24.13
Not Affected
openwrt
master
1.26.4-r2
Not Affected
openwrt
openwrt-25.12
1.26.4-r2
Not Affected
yocto
kirkstone
1.20.7
Not Affected
yocto
kirkstone
1.20.7
Patched
yocto
master
1.28.4
Not Affected
yocto
master
1.28.4
Not Affected
Resolved with patches#
gstreamer1.0-plugins-good (yocto:kirkstone)
#
Title
Author
Resolve
1
wavparse: Fix parsing of acid chunk
=?UTF-8?q?Sebastian=20Dr=C3=B6ge?= <sebastian@centricular.com>
CVE-2024-47775
CVE-2024-47776
CVE-2024-47777
CVE-2024-47778
2
wavparse: Check for short reads when parsing headers in pull
=?UTF-8?q?Sebastian=20Dr=C3=B6ge?= <sebastian@centricular.com>
CVE-2024-47775
CVE-2024-47776
CVE-2024-47777
CVE-2024-47778
3
wavparse: Fix clipping of size to the file size
=?UTF-8?q?Sebastian=20Dr=C3=B6ge?= <sebastian@centricular.com>
CVE-2024-47775
CVE-2024-47776
CVE-2024-47777
CVE-2024-47778
4
wavparse: Make sure enough data for the tag list tag is
=?UTF-8?q?Sebastian=20Dr=C3=B6ge?= <sebastian@centricular.com>
CVE-2024-47775
CVE-2024-47776
CVE-2024-47777
CVE-2024-47778
5
wavparse: Check size before reading ds64 chunk
=?UTF-8?q?Sebastian=20Dr=C3=B6ge?= <sebastian@centricular.com>
CVE-2024-47775
CVE-2024-47776
CVE-2024-47777
CVE-2024-47778
6
wavparse: Check that at least 32 bytes are available before
=?UTF-8?q?Sebastian=20Dr=C3=B6ge?= <sebastian@centricular.com>
CVE-2024-47775
CVE-2024-47776
CVE-2024-47777
CVE-2024-47778
7
wavparse: Check that at least 4 bytes are available before
=?UTF-8?q?Sebastian=20Dr=C3=B6ge?= <sebastian@centricular.com>
CVE-2024-47775
CVE-2024-47776
CVE-2024-47777
CVE-2024-47778
gstreamer1.0-plugins-good (yocto:scarthgap)
#
Title
Author
Resolve
1
wavparse: Check for short reads when parsing headers in
=?UTF-8?q?Sebastian=20Dr=C3=B6ge?= <sebastian@centricular.com>
CVE-2024-47775
CVE-2024-47776
CVE-2024-47777
CVE-2024-47778
2
wavparse: Check that at least 4 bytes are available
=?UTF-8?q?Sebastian=20Dr=C3=B6ge?= <sebastian@centricular.com>
CVE-2024-47775
CVE-2024-47776
CVE-2024-47777
CVE-2024-47778
3
wavparse: Fix parsing of acid chunk
=?UTF-8?q?Sebastian=20Dr=C3=B6ge?= <sebastian@centricular.com>
CVE-2024-47775
CVE-2024-47776
CVE-2024-47777
CVE-2024-47778
4
wavparse: Make sure enough data for the tag list tag is
=?UTF-8?q?Sebastian=20Dr=C3=B6ge?= <sebastian@centricular.com>
CVE-2024-47775
CVE-2024-47776
CVE-2024-47777
CVE-2024-47778
5
wavparse: Fix clipping of size to the file size
=?UTF-8?q?Sebastian=20Dr=C3=B6ge?= <sebastian@centricular.com>
CVE-2024-47775
CVE-2024-47776
CVE-2024-47777
CVE-2024-47778
6
wavparse: Check that at least 32 bytes are available
=?UTF-8?q?Sebastian=20Dr=C3=B6ge?= <sebastian@centricular.com>
CVE-2024-47775
CVE-2024-47776
CVE-2024-47777
CVE-2024-47778
7
wavparse: Check size before reading ds64 chunk
=?UTF-8?q?Sebastian=20Dr=C3=B6ge?= <sebastian@centricular.com>
CVE-2024-47775
CVE-2024-47776
CVE-2024-47777
CVE-2024-47778