Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-9928

Опубликовано: 24 апр. 2019
Источник: debian

Описание

GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection parser via a crafted response from a server, potentially allowing remote code execution.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gst-plugins-base1.0fixed1.15.90-1experimentalpackage
gst-plugins-base1.0fixed1.14.4-2package
gst-plugins-base0.10removedpackage

Примечания

  • https://gstreamer.freedesktop.org/security/sa-2019-0001.html

  • https://gitlab.freedesktop.org/gstreamer/gst-plugins-base/merge_requests/157

  • https://gitlab.freedesktop.org/gstreamer/gst-plugins-base/commit/f672277509705c4034bc92a141eefee4524d15aa (1.15.90)

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 7 лет назад

GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection parser via a crafted response from a server, potentially allowing remote code execution.

CVSS3: 7.5
redhat
больше 7 лет назад

GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection parser via a crafted response from a server, potentially allowing remote code execution.

CVSS3: 8.8
nvd
больше 7 лет назад

GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection parser via a crafted response from a server, potentially allowing remote code execution.

suse-cvrf
больше 6 лет назад

Security update for gstreamer-plugins-base

suse-cvrf
около 7 лет назад

Security update for gstreamer-plugins-base