Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-0397

Опубликовано: 03 фев. 2009
Источник: nvd
CVSS2: 9.3
EPSS Средний

Описание

Heap-based buffer overflow in the qtdemux_parse_samples function in gst/qtdemux/qtdemux.c in GStreamer Good Plug-ins (aka gst-plugins-good) 0.10.9 through 0.10.11, and GStreamer Plug-ins (aka gstreamer-plugins) 0.8.5, might allow remote attackers to execute arbitrary code via crafted Time-to-sample (aka stts) atom data in a malformed QuickTime media .mov file.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:gstreamer:good_plug-ins:0.10.9:*:*:*:*:*:*:*
cpe:2.3:a:gstreamer:good_plug-ins:0.10.10:*:*:*:*:*:*:*
cpe:2.3:a:gstreamer:good_plug-ins:0.10.11:*:*:*:*:*:*:*
cpe:2.3:a:gstreamer:plug-ins:0.8.5:*:*:*:*:*:*:*

EPSS

Процентиль: 93%
0.10426
Средний

9.3 Critical

CVSS2

Дефекты

CWE-119

Связанные уязвимости

ubuntu
больше 16 лет назад

Heap-based buffer overflow in the qtdemux_parse_samples function in gst/qtdemux/qtdemux.c in GStreamer Good Plug-ins (aka gst-plugins-good) 0.10.9 through 0.10.11, and GStreamer Plug-ins (aka gstreamer-plugins) 0.8.5, might allow remote attackers to execute arbitrary code via crafted Time-to-sample (aka stts) atom data in a malformed QuickTime media .mov file.

redhat
больше 16 лет назад

Heap-based buffer overflow in the qtdemux_parse_samples function in gst/qtdemux/qtdemux.c in GStreamer Good Plug-ins (aka gst-plugins-good) 0.10.9 through 0.10.11, and GStreamer Plug-ins (aka gstreamer-plugins) 0.8.5, might allow remote attackers to execute arbitrary code via crafted Time-to-sample (aka stts) atom data in a malformed QuickTime media .mov file.

debian
больше 16 лет назад

Heap-based buffer overflow in the qtdemux_parse_samples function in gs ...

github
около 3 лет назад

Heap-based buffer overflow in the qtdemux_parse_samples function in gst/qtdemux/qtdemux.c in GStreamer Good Plug-ins (aka gst-plugins-good) 0.10.9 through 0.10.11, and GStreamer Plug-ins (aka gstreamer-plugins) 0.8.5, might allow remote attackers to execute arbitrary code via crafted Time-to-sample (aka stts) atom data in a malformed QuickTime media .mov file.

oracle-oval
больше 16 лет назад

ELSA-2009-0271: gstreamer-plugins-good security update (IMPORTANT)

EPSS

Процентиль: 93%
0.10426
Средний

9.3 Critical

CVSS2

Дефекты

CWE-119