PT-2009-6715 · Gstreamer+1 · Gstreamer Good Plug-Ins+1

Tielei Wang

·

Publicado

1970-01-01

·

Atualizado

2017-09-29

·

CVE-2009-1932

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions GStreamer Good Plug-ins versions 0.10.15
Description The issue is caused by multiple integer overflows in the user info callback, user endrow callback, and gst pngdec task functions, which can lead to a denial of service and possibly allow remote attackers to execute arbitrary code via a crafted PNG file, triggering a buffer overflow. The vulnerability can be exploited remotely, potentially disrupting the confidentiality, integrity, and availability of protected information.
Recommendations For GStreamer Good Plug-ins version 0.10.15, consider updating to a newer version to mitigate the risk, as the current version contains multiple integer overflows that can be exploited. As a temporary workaround, consider restricting the use of the gst pngdec task function and the user info callback and user endrow callback functions until a patch is available. Avoid using crafted PNG files that can trigger the buffer overflow.

Exploit

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-03393
BDU:2015-03394
BDU:2015-03395
BDU:2015-03396
CVE-2009-1932
DSA-1839-1
RHSA-2009:1123
RHSA-2009_1123

Produtos afetados

Gstreamer Good Plug-Ins
Red Hat