CVE-2024-40897
published 2024-07-26CVE-2024-40897: Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file…
PriorityP432medium6.7CVSS 3.1
AVLACHPRLUIRSUCHIHAH
EPSS
0.38%
30.2th percentile
Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | orc | >= 0 < 1:0.4.39-1 | 1:0.4.39-1 |
| apache | orc | >= 0 < 1:0.4.39-1 | 1:0.4.39-1 |
| debian | orc | < orc 1:0.4.39-1 (forky) | orc 1:0.4.39-1 (forky) |
| gstreamer | orc | < 0.4.39 | 0.4.39 |
| gstreamer | orc | — | — |
| msrc | azl3_orc_0.4.39-2_on_azure_linux_3.0 | — | — |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
osv6.7MEDIUM
vendor_msrc7.0HIGH
vendor_debian6.7MEDIUM
vendor_redhat6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
ORC vulnerability
vendor_ubuntu·2024-10-01
CVE-2024-40897 ORC vulnerability
Title: ORC vulnerability
Summary: ORC could be made to crash or execute arbitrary code
USN-6964-1 fixed a vulnerability in ORC. This update provides the
corresponding updates for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
Original advisory details:
Noriko Totsuka discovered that ORC incorrectly handled certain
specially crafted files. An attacker could possibly use this issue
to execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
ORC vulnerability
vendor_ubuntu·2024-08-15
CVE-2024-40897 ORC vulnerability
Title: ORC vulnerability
Summary: ORC could be made to crash or execute arbitrary code
Noriko Totsuka discovered that ORC incorrectly handled certain
crafted file. An attacker could possibly use this issue to execute
arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
orc: Stack-based buffer overflow vulnerability in ORC
vendor_redhat·2024-07-26·CVSS 6.7
CVE-2024-40897 [MEDIUM] orc: Stack-based buffer overflow vulnerability in ORC
orc: Stack-based buffer overflow vulnerability in ORC
Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments.
Stack-based buffer overflow vulnerability exists in orcparse.c of ORC. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments.
Mitigation: Mitigation for this issue is either not available or the currently available opt
Microsoft
Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitra
vendor_msrc·2024-07-09·CVSS 7.0
CVE-2024-40897 [MEDIUM] CWE-787 Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitra
Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publish
Debian
CVE-2024-40897: orc - Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions p...
vendor_debian·2024·CVSS 6.7
CVE-2024-40897 [MEDIUM] CVE-2024-40897: orc - Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions p...
Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1:0.4.39-1)
sid: resolved (fixed in 1:0.4.39-1)
trixie: resolved (fixed in 1:0.4.39-1)
OSV
CVE-2024-40897: Stack-based buffer overflow vulnerability exists in orcparse
osv·2024-07-26·CVSS 6.7
CVE-2024-40897 [MEDIUM] CVE-2024-40897: Stack-based buffer overflow vulnerability exists in orcparse
Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments.
GHSA
GHSA-247v-6wr5-3wf3: Stack-based buffer overflow vulnerability exists in orcparse
ghsa_unreviewed·2024-07-26
CVE-2024-40897 [HIGH] CWE-121 GHSA-247v-6wr5-3wf3: Stack-based buffer overflow vulnerability exists in orcparse
Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2024/07/26/1https://github.com/GStreamer/orchttps://gstreamer.freedesktop.org/modules/orc.htmlhttps://jvn.jp/en/jp/JVN02030803/http://www.openwall.com/lists/oss-security/2024/07/26/1https://github.com/GStreamer/orchttps://gstreamer.freedesktop.org/modules/orc.htmlhttps://jvn.jp/en/jp/JVN02030803/
2024-07-26
Published