Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-9928

Опубликовано: 22 апр. 2019
Источник: redhat
CVSS3: 7.5

Описание

GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection parser via a crafted response from a server, potentially allowing remote code execution.

Отчет

This issue affects the version of gstreamer-plugins-base and gstreamer1-plugins-base as shipped with Red Hat Enterprise Linux 6, 7 and 8. The security impact has been rated as Moderate by the Red Hat Product Security team. Red Hat Enterprise Linux 6 is now in Maintenance Support 2 Phase of the support and maintenance life cycle. This has been rated as having a security impact of Moderate, and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5gstreamer-plugins-baseOut of support scope
Red Hat Enterprise Linux 6gstreamer-plugins-baseOut of support scope
Red Hat Enterprise Linux 7gstreamer1-plugins-baseWill not fix
Red Hat Enterprise Linux 7gstreamer-plugins-baseWill not fix
Red Hat Enterprise Linux 8gstreamer1-plugins-baseFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1724904GStreamer: heap-based buffer overflow in the RTSP connection parser via crafted server response leading to remote code execution

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 7 лет назад

GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection parser via a crafted response from a server, potentially allowing remote code execution.

CVSS3: 8.8
nvd
почти 7 лет назад

GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection parser via a crafted response from a server, potentially allowing remote code execution.

CVSS3: 8.8
debian
почти 7 лет назад

GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP c ...

suse-cvrf
больше 5 лет назад

Security update for gstreamer-plugins-base

suse-cvrf
больше 6 лет назад

Security update for gstreamer-plugins-base

7.5 High

CVSS3