Description

Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments.

INFO

Published Date :

2024-07-26T06:03:23.768Z

Last Modified :

2025-02-13T17:53:28.546Z

Source :

jpcert
AFFECTED PRODUCTS

The following products are affected by CVE-2024-40897 vulnerability.

Vendors Products
Gstreamer
  • Orc
Redhat
  • Enterprise Linux
  • Rhel Aus
  • Rhel E4s
  • Rhel Eus
  • Rhel Tus

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact