PT-2009-6715 · Gstreamer+1 · Gstreamer Good Plug-Ins+1
Tielei Wang
·
Published
1970-01-01
·
Updated
2017-09-29
·
CVE-2009-1932
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
GStreamer Good Plug-ins versions 0.10.15
Description
The issue is caused by multiple integer overflows in the
user info callback, user endrow callback, and gst pngdec task functions, which can lead to a denial of service and possibly allow remote attackers to execute arbitrary code via a crafted PNG file, triggering a buffer overflow. The vulnerability can be exploited remotely, potentially disrupting the confidentiality, integrity, and availability of protected information.Recommendations
For GStreamer Good Plug-ins version 0.10.15, consider updating to a newer version to mitigate the risk, as the current version contains multiple integer overflows that can be exploited. As a temporary workaround, consider restricting the use of the
gst pngdec task function and the user info callback and user endrow callback functions until a patch is available. Avoid using crafted PNG files that can trigger the buffer overflow.Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gstreamer Good Plug-Ins
Red Hat