GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been identified in the gst_wavparse_smpl_chunk function within gstwavparse.c. This function attempts to read 4 bytes from the data + 12 offset without checking if the size of the data buffer is sufficient. If the buffer is too small, the function reads beyond its bounds. This vulnerability may result in reading 4 bytes out of the boundaries of the data buffer. This vulnerability is fixed in 1.24.10.
Tags
#active-directory #advisory #agency #ai #airport #alert #analysis #anarchism #android #antivirus #api #apt #archive #article #asm #assembly #attack #audiobook #automotive #balloon #binary-exploitation #blockchain #blog #blueteam #browser #bugbounty #c2 #career #certificate #challenge #chatbot #cheatsheet #cipher #cloud #community #conference #container #course #cpu #crime #crypto #cryptocurrency #cryptography #ctf #cve #cwe #cyberattack #cybercrime #darknet #darkweb #data-breach #database #dataset #digital #directory #dns #document #domain #edr #electro #email #encryption #evasion #event #exploit #feed #forensics #forum #gadget #game #geolocation #gpt #guide #hackathon #hacking #hardware #hash #history #identity #image #infrastructure #interconnection #internet #ioc #ip #job #journal #kernel #kubernetes #learn #lei #linux #llm #machine-learning #macos #magazine #malware #microsoft #mobile #monitor #network #news #onion #open-source #os #osint #ot #paper #password #payload #pcap #pentest #pentesting #persistence #philosophy #phishing #poc #podcast #privacy #product #prompt-injection #quantum #railway #ransomware #realtime #reconnaissance #redteam #report #research #resource #resources #reverse-engineering #rfc #safe #sandbox #satellite #scam #scan #search-engine #secure-coding #security-clearance #server #setup #shadow-library #smart-contract #social #social-engineering #source-code #ssl #ssn #storage #subdomain #surveillance #syscall #table #technique #techniques #technology #thread #threat #tips #tls #tool #tools #track #traffic #train #training #trends #ttp #tutorial #vehicle #vin #virus #vpn #vulnerability #wargame #web #web3 #webcam #webrtc #wiki #windows #winodws #wordlist #writeup #youtube