Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-33x5-f9c4-3q24

Опубликовано: 15 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.1

Описание

An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. The JPEG parser reads a segment length value from the bitstream without validating it against available data. A remote attacker could trick a user into opening a specially crafted JPEG file, causing downstream parsing to read beyond the provided input buffer, leading to a crash or potential information disclosure.

An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. The JPEG parser reads a segment length value from the bitstream without validating it against available data. A remote attacker could trick a user into opening a specially crafted JPEG file, causing downstream parsing to read beyond the provided input buffer, leading to a crash or potential information disclosure.

EPSS

Процентиль: 20%
0.0028
Низкий

7.1 High

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 7.1
ubuntu
около 2 месяцев назад

An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. The JPEG parser reads a segment length value from the bitstream without validating it against available data. A remote attacker could trick a user into opening a specially crafted JPEG file, causing downstream parsing to read beyond the provided input buffer, leading to a crash or potential information disclosure.

CVSS3: 7.1
redhat
около 2 месяцев назад

An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. The JPEG parser reads a segment length value from the bitstream without validating it against available data. A remote attacker could trick a user into opening a specially crafted JPEG file, causing downstream parsing to read beyond the provided input buffer, leading to a crash or potential information disclosure.

CVSS3: 7.1
nvd
около 2 месяцев назад

An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. The JPEG parser reads a segment length value from the bitstream without validating it against available data. A remote attacker could trick a user into opening a specially crafted JPEG file, causing downstream parsing to read beyond the provided input buffer, leading to a crash or potential information disclosure.

CVSS3: 7.1
debian
около 2 месяцев назад

An out-of-bounds read vulnerability was found in the VA JPEG decoder i ...

suse-cvrf
29 дней назад

Security update for gstreamer-plugins-bad

EPSS

Процентиль: 20%
0.0028
Низкий

7.1 High

CVSS3

Дефекты

CWE-125