ZeroHour

CVE-2024-40897

CVSS 3.1
6.7 medium
EPSS
<1%p31
Published
()
Modified
Description

Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments.

Vendors
gstreamer
Products
orc
Weakness
CWE-787, CWE-121
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.