PT-2009-6715 · Gstreamer+1 · Gstreamer Good Plug-Ins+1
Tielei Wang
·
Publicado
1970-01-01
·
Atualizado
2017-09-29
·
CVE-2009-1932
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
GStreamer Good Plug-ins versions 0.10.15
Description
The issue is caused by multiple integer overflows in the
user info callback, user endrow callback, and gst pngdec task functions, which can lead to a denial of service and possibly allow remote attackers to execute arbitrary code via a crafted PNG file, triggering a buffer overflow. The vulnerability can be exploited remotely, potentially disrupting the confidentiality, integrity, and availability of protected information.Recommendations
For GStreamer Good Plug-ins version 0.10.15, consider updating to a newer version to mitigate the risk, as the current version contains multiple integer overflows that can be exploited. As a temporary workaround, consider restricting the use of the
gst pngdec task function and the user info callback and user endrow callback functions until a patch is available. Avoid using crafted PNG files that can trigger the buffer overflow.Exploit
Correção
DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Gstreamer Good Plug-Ins
Red Hat