Stack-based buffer overflow in gstreamer - CVE-2024-0444

 

Stack-based buffer overflow in gstreamer - CVE-2024-0444

Published: June 5, 2024


Vulnerability identifier: #VU91245
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-0444
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when parsing AV1-encoded video files. A remote attacker can trick the victim to open a specially crafted video file, trigger a stack-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

gstreamer
Debian Linux
Anolis OS
Ubuntu
Fedora
gst-plugins-bad1.0 (Ubuntu package)
gst-plugins-bad1.0 (Debian package)
gstreamer1-plugins-bad-free-doc
gstreamer1-plugins-bad-free-devel
gstreamer1-plugins-bad-free
mingw-gstreamer1-plugins-bad-free
mingw-gstreamer1-plugins-good
mingw-gstreamer1
mingw-gstreamer1-plugins-base
gstreamer1
gstreamer1-devel
gstreamer1-plugins-bad-free-libs
mingw-python-urllib3

How to mitigate CVE-2024-0444

Install updates from vendor's website.

gst-plugins-bad1.0 (Ubuntu package) - addressed in versions 1.16.3-0ubuntu1.1+esm1, 1.20.3-0ubuntu1.1+esm2, 1.24.2-1ubuntu4+esm1, 1.24.8-2ubuntu1.1, 1.26.0-1ubuntu2.1
gst-plugins-bad1.0 (Debian package) - addressed in versions 1.18.4-3+deb11u4, 1.22.0-4+deb12u5
gstreamer1-plugins-bad-free-doc - update to 1.22.6-3
gstreamer1-plugins-bad-free-devel - addressed in versions 1.22.6-3, 1.22.12-3.0.1
gstreamer1-plugins-bad-free - addressed in versions 1.22.6-3, 1.22.12-3.0.1
mingw-gstreamer1-plugins-bad-free - addressed in versions 1.22.7-2.fc39, 1.22.9-1.fc39
mingw-gstreamer1-plugins-good - update to 1.22.9-1.fc39
mingw-gstreamer1 - update to 1.22.9-1.fc39
mingw-gstreamer1-plugins-base - update to 1.22.9-2.fc39
gstreamer1 - update to 1.22.12-3.0.1
gstreamer1-devel - update to 1.22.12-3.0.1
gstreamer1-plugins-bad-free-libs - update to 1.22.12-3.0.1
mingw-python-urllib3 - addressed in versions 1.26.19-1.fc39, 1.26.19-1.fc40

External References

Related Security Bulletins