Описание
GStreamer PNG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of PNG files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29581.
A flaw was found in GStreamer. This vulnerability, a heap-based buffer overflow during PNG file parsing, allows a remote attacker to execute arbitrary code. Successful exploitation requires user interaction, such as opening a malicious PNG file or visiting a specially crafted web page. The issue arises from inadequate validation of user-supplied data length, which can lead to code execution within the context of the affected process.
Меры по смягчению последствий
To reduce the risk of exploitation, users should avoid opening or processing untrusted PNG files from unknown or suspicious sources. This operational control is crucial as the vulnerability requires user interaction to trigger the heap-based buffer overflow.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | gstreamer-plugins-good | Not affected | ||
| Red Hat Enterprise Linux 7 | gstreamer1-plugins-good | Affected | ||
| Red Hat Enterprise Linux 7 | gstreamer-plugins-good | Not affected | ||
| Red Hat Enterprise Linux 8 | mingw-gstreamer1-plugins-good | Affected | ||
| Red Hat Enterprise Linux 10 | gstreamer1-plugins-good | Fixed | RHSA-2026:59133 | 24.08.2026 |
| Red Hat Enterprise Linux 8 | gstreamer1-plugins-good | Fixed | RHSA-2026:59179 | 24.08.2026 |
| Red Hat Enterprise Linux 9 | gstreamer1-plugins-good | Fixed | RHSA-2026:59152 | 24.08.2026 |
Показывать по
Дополнительная информация
Статус:
7.8 High
CVSS3
Связанные уязвимости
GStreamer PNG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PNG files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29581.
GStreamer PNG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PNG files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29581.
GStreamer PNG File Parsing Heap-based Buffer Overflow Remote Code Exec ...
7.8 High
CVSS3