Bug 2282999 (CVE-2024-4453)
Summary: | CVE-2024-4453 gstreamer: EXIF Metadata Parsing Integer Overflow | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Pedro Sampaio <psampaio> |
Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
Status: | NEW --- | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | ndegraef |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | If docs needed, set a value | |
Doc Text: |
A flaw was found in the GStreamer library. This flaw allows a remote attacker to send specially crafted content to the victim, allowing for arbitrary code execution within the context of the affected installation's process. The vulnerability is caused by improper parsing of EXIF metadata and a lack of proper validation of user-supplied data, which triggers an integer overflow.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | Type: | --- | |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2283000, 2283001, 2302854 | ||
Bug Blocks: | 2283007 |
Description
Pedro Sampaio
2024-05-23 14:34:10 UTC
Created gstreamer1 tracking bugs for this issue: Affects: fedora-all [bug 2283000] Created mingw-gstreamer1 tracking bugs for this issue: Affects: fedora-all [bug 2283001] This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2024:9056 https://access.redhat.com/errata/RHSA-2024:9056 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:7178 https://access.redhat.com/errata/RHSA-2025:7178 |