GStreamer is a library for constructing graphs of media-handling components. A stack-buffer overflow has been detected in the vorbis_handle_identification_packet function within gstvorbisdec.c. The position array is a stack-allocated buffer of size 64. If vd->vi.channels exceeds 64, the for loop will write beyond the boundaries of the position array The value written will always be GST_AUDIO_CHANNEL_POSITION_NONE. This vulnerability allows to overwrite the EIP address allocated in the stack. Additionally, this bug can overwrite the GstAudioInfo info structure. This vulnerability is fixed in 1.24.10.
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2024:11120 https://access.redhat.com/errata/RHSA-2024:11120
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Extended Update Support Via RHSA-2024:11117 https://access.redhat.com/errata/RHSA-2024:11117
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2024:11118 https://access.redhat.com/errata/RHSA-2024:11118
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:11123 https://access.redhat.com/errata/RHSA-2024:11123
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2024:11130 https://access.redhat.com/errata/RHSA-2024:11130
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Telecommunications Update Service Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions Via RHSA-2024:11143 https://access.redhat.com/errata/RHSA-2024:11143
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2024:11141 https://access.redhat.com/errata/RHSA-2024:11141
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Extended Update Support Via RHSA-2024:11142 https://access.redhat.com/errata/RHSA-2024:11142
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2024:11344 https://access.redhat.com/errata/RHSA-2024:11344
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2024:11345 https://access.redhat.com/errata/RHSA-2024:11345