CVE-2024-40897
Last modified
CVE-2024-40897 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments.
Metrics
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gstreamer | Orc | < 0.4.39 |
References
- http://www.openwall.com/lists/oss-security/2024/07/26/1Third Party Advisory
- https://jvn.jp/en/jp/JVN02030803/Third Party Advisory
- http://www.openwall.com/lists/oss-security/2024/07/26/1Third Party Advisory
- https://jvn.jp/en/jp/JVN02030803/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-40897?
How severe is CVE-2024-40897?
How do I fix CVE-2024-40897?
Are you affected by CVE-2024-40897?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
