漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
GHSL-2024-243: GStreamer has an integer underflow in extract_cc_from_data leading to OOB-read
Vulnerability Description
GStreamer is a library for constructing graphs of media-handling components. An integer underflow has been detected in extract_cc_from_data function within qtdemux.c. In the FOURCC_c708 case, the subtraction atom_length - 8 may result in an underflow if atom_length is less than 8. When that subtraction underflows, *cclen ends up being a large number, and then cclen is passed to g_memdup2 leading to an out-of-bounds (OOB) read. This vulnerability is fixed in 1.24.10.
CVSS Information
N/A
Vulnerability Type
整数下溢(超界折返)
Vulnerability Title
GStreamer 数字错误漏洞
Vulnerability Description
GStreamer是GStreamer开源的一套用于处理流媒体的框架。 GStreamer 1.24.10之前版本存在数字错误漏洞,该漏洞源于在qtdemux.c中的extract_cc_from_data函数中检测到整数下溢。
CVSS Information
N/A
Vulnerability Type
N/A