Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-40897

Опубликовано: 26 июл. 2024
Источник: nvd
CVSS3: 6.7
CVSS3: 7
EPSS Низкий

Описание

Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gstreamer:orc:*:*:*:*:*:*:*:*
Версия до 0.4.39 (исключая)

EPSS

Процентиль: 10%
0.00037
Низкий

6.7 Medium

CVSS3

7 High

CVSS3

Дефекты

CWE-787
CWE-121

Связанные уязвимости

CVSS3: 6.7
ubuntu
около 1 года назад

Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments.

CVSS3: 6.7
redhat
около 1 года назад

Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments.

CVSS3: 6.7
msrc
6 месяцев назад

Описание отсутствует

CVSS3: 6.7
debian
около 1 года назад

Stack-based buffer overflow vulnerability exists in orcparse.c of ORC ...

suse-cvrf
6 месяцев назад

Security update for orc

EPSS

Процентиль: 10%
0.00037
Низкий

6.7 Medium

CVSS3

7 High

CVSS3

Дефекты

CWE-787
CWE-121