Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19389

Опубликовано: 05 авг. 2026
Источник: redhat
CVSS3: 7.1

Описание

Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled length and size values can bypass bounds checks and cause out-of-bounds heap reads. This can result in application crash, denial of service, or limited information disclosure when untrusted media is processed.

Отчет

This is an Important flaw. Integer overflow and underflow vulnerabilities in the GStreamer ASF demuxer can lead to a denial of service and limited heap information disclosure. This occurs when processing specially crafted ASF/WMV/WMA files, a risk amplified by the demuxer being automatically utilized by GStreamer's common playback elements in Red Hat products.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10gstreamer1-plugins-ugly-freeAffected
Red Hat Enterprise Linux 7gstreamer1-plugins-ugly-freeAffected
Red Hat Enterprise Linux 8gstreamer1-plugins-ugly-freeAffected
Red Hat Enterprise Linux 9gstreamer1-plugins-ugly-freeAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2513016gstreamer: gstreamer1-plugins-ugly-free: gstreamer: integer overflow/underflow in asfdemux bounds checks leading to out-of-bounds read

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
7 дней назад

Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled length and size values can bypass bounds checks and cause out-of-bounds heap reads. This can result in application crash, denial of service, or limited information disclosure when untrusted media is processed.

CVSS3: 7.1
nvd
7 дней назад

Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled length and size values can bypass bounds checks and cause out-of-bounds heap reads. This can result in application crash, denial of service, or limited information disclosure when untrusted media is processed.

CVSS3: 7.1
debian
7 дней назад

Multiple integer overflow and underflow vulnerabilities were found in ...

CVSS3: 7.1
github
7 дней назад

Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled length and size values can bypass bounds checks and cause out-of-bounds heap reads. This can result in application crash, denial of service, or limited information disclosure when untrusted media is processed.

7.1 High

CVSS3