PT-2024-3659 · Gstreamer+9 · Gstreamer+9

Michael Randrianantenaina

·

Published

2024-04-17

·

Updated

2025-10-07

·

CVE-2024-4453

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GStreamer (affected versions not specified)
Description The issue is related to an integer overflow when handling EXIF metadata in files, allowing remote attackers to execute arbitrary code on affected installations. The flaw exists within the parsing of EXIF metadata due to the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:9056
ALSA-2025:7178
AZL-43432
AZL-45048
BDU:2024-04000
CESA-2024_9056
CVE-2024-4453
DLA-3824-1
DSA-5702-1
INFSA-2024_9056
INFSA-2025_7178
MGASA-2024-0215
OPENSUSE-SU-2024:14005-1
OPENSUSE-SU-2024_1882-1
OPENSUSE-SU-2024_1910-1
RHSA-2024:9056
RHSA-2024_9056
RHSA-2025:7178
RHSA-2025_7178
RLSA-2024:9056
SUSE-SU-2024:1882-1
SUSE-SU-2024:1882-2
SUSE-SU-2024:1886-1
SUSE-SU-2024:1893-1
SUSE-SU-2024:1910-1
SUSE-SU-2024:1945-1
SUSE-SU-2024_1882-1
SUSE-SU-2024_1886-1
SUSE-SU-2024_1893-1
SUSE-SU-2024_1910-1
SUSE-SU-2024_1945-1
USN-6798-1
USN-7807-1
ZDI-24-467

Affected Products

Almalinux
Astra Linux
Centos
Gstreamer
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu