PT-2024-26086 · Unknown · Librtppayload.So

Yifei Xie

·

Published

2024-10-07

·

Updated

2024-10-30

·

CVE-2024-34665

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions librtppayload.so versions prior to SMR Oct-2024 Release 1
Description The issue is an out-of-bounds write in parsing h.264 format, allowing remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this issue.
Recommendations For versions prior to SMR Oct-2024 Release 1, update to SMR Oct-2024 Release 1 or later to resolve the issue. As a temporary workaround, consider restricting access to the librtppayload.so module to minimize the risk of exploitation.

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2024-34665

Affected Products

Librtppayload.So