Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-52720

Опубликовано: 15 июн. 2026
Источник: debian
EPSS Низкий

Описание

A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a malicious VNC server to send a rectangle that extends beyond the framebuffer. A remote attacker could set up a malicious VNC server and trick a user into connecting, resulting in an out-of-bounds heap write that could lead to code execution or a crash.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gst-plugins-bad1.0fixed1.28.5-1package
gst-plugins-bad1.0no-dsatrixiepackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2486731

  • https://gstreamer.freedesktop.org/security/sa-2026-0043.html

  • https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5105 (private)

  • https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/f3b66928a194b32b27fac3c3379d3d20e5966442 (1.29.2)

  • https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/219328eba2ea082c08193a12887cc2ce0dc70b9b (1.28.5)

  • https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/1ca88138fb0f8562861956b66a0c98406bcb7370 (1.26 branch)

EPSS

Процентиль: 47%
0.00638
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 2 месяцев назад

A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a malicious VNC server to send a rectangle that extends beyond the framebuffer. A remote attacker could set up a malicious VNC server and trick a user into connecting, resulting in an out-of-bounds heap write that could lead to code execution or a crash.

CVSS3: 8.8
redhat
около 2 месяцев назад

A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a malicious VNC server to send a rectangle that extends beyond the framebuffer. A remote attacker could set up a malicious VNC server and trick a user into connecting, resulting in an out-of-bounds heap write that could lead to code execution or a crash.

CVSS3: 8.8
nvd
около 2 месяцев назад

A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a malicious VNC server to send a rectangle that extends beyond the framebuffer. A remote attacker could set up a malicious VNC server and trick a user into connecting, resulting in an out-of-bounds heap write that could lead to code execution or a crash.

CVSS3: 8.8
github
около 2 месяцев назад

A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a malicious VNC server to send a rectangle that extends beyond the framebuffer. A remote attacker could set up a malicious VNC server and trick a user into connecting, resulting in an out-of-bounds heap write that could lead to code execution or a crash.

rocky
21 день назад

Important: gstreamer1-plugins-bad-free security update

EPSS

Процентиль: 47%
0.00638
Низкий