PT-2009-6715 · Gstreamer+1 · Gstreamer Good Plug-Ins+1

Tielei Wang

·

Published

1970-01-01

·

Updated

2017-09-29

·

CVE-2009-1932

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions GStreamer Good Plug-ins versions 0.10.15
Description The issue is caused by multiple integer overflows in the user info callback, user endrow callback, and gst pngdec task functions, which can lead to a denial of service and possibly allow remote attackers to execute arbitrary code via a crafted PNG file, triggering a buffer overflow. The vulnerability can be exploited remotely, potentially disrupting the confidentiality, integrity, and availability of protected information.
Recommendations For GStreamer Good Plug-ins version 0.10.15, consider updating to a newer version to mitigate the risk, as the current version contains multiple integer overflows that can be exploited. As a temporary workaround, consider restricting the use of the gst pngdec task function and the user info callback and user endrow callback functions until a patch is available. Avoid using crafted PNG files that can trigger the buffer overflow.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-03393
BDU:2015-03394
BDU:2015-03395
BDU:2015-03396
CVE-2009-1932
DSA-1839-1
RHSA-2009:1123
RHSA-2009_1123

Affected Products

Gstreamer Good Plug-Ins
Red Hat