CVE-2024-40897 is a stack-based buffer overflow vulnerability in ORC versions prior to 0.4.39, specifically within the orcparse.c component, affecting gstreamer orc. A successful attack requires a developer to process a specially crafted file, potentially leading to arbitrary code execution on their build environment or CI systems. With a CVSS score of 6.7 (Medium), exploitation is complex (AC:H) and requires user interaction (UI:R), but can result in high impact to confidentiality, integrity, and availability (C:H/I:H/A:H). There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.4.39CPE matchmatch criteria | cpe:2.3:a:gstreamer:orc:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP4 Security Updates
Oct 29, 2024HP ThinPro 8.1 SP4 Security Updates
Oct 29, 2024orc: Stack-based buffer overflow vulnerability in ORC
Jul 26, 2024Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments.
Jul 9, 2024