PT-2009-3229 · Gstreamer+1 · Gst-Plugins-Base+1

Tomas Hoger

·

Published

2009-03-14

·

Updated

2023-02-13

·

CVE-2009-0586

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions gst-plugins-base versions prior to 0.10.23
Description The issue is related to an integer overflow in the gst vorbis tag add coverart function, which can lead to a heap-based buffer overflow. This occurs when a crafted COVERART tag, converted from a base64 representation, is processed. The overflow can be exploited by context-dependent attackers to execute arbitrary code.
Recommendations For versions prior to 0.10.23, update to version 0.10.23 or later to resolve the issue. As a temporary workaround, consider restricting the processing of COVERART tags from untrusted sources until the update is applied.

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-0586
RHSA-2009:0352
RHSA-2009_0352

Affected Products

Red Hat
Gst-Plugins-Base