Описание
Multiple out-of-bounds read vulnerabilities were found in GStreamer's pcapparse element. Malformed PCAP records can trigger reads beyond buffer boundaries during IPv4/TCP header parsing. This element is primarily used in debugging pipelines, limiting real-world exposure. A local attacker could trick a user into processing a specially crafted PCAP file, potentially leading to a crash or information disclosure.
Отчет
This is a Moderate out-of-bounds read vulnerability in the GStreamer pcapparse element (gst-plugins-bad). The flaw allows reads beyond buffer boundaries when processing malformed PCAP records due to missing bounds validation on IPv4/TCP header fields and untrusted IP packet length values. The impact is limited because the pcapparse element is primarily used in debugging pipelines, not in standard media playback workflows. The upstream maintainer confirmed this can only be triggered in specially crafted GStreamer pipelines built for debugging purposes, making real-world exploitation very unlikely. Red Hat products utilizing GStreamer for multimedia processing are affected only if they use the pcapparse element in custom debugging pipelines.
Меры по смягчению последствий
Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | gstreamer1-plugins-bad-free | Fix deferred | ||
| Red Hat Enterprise Linux 6 | gstreamer-plugins-bad-free | Out of support scope | ||
| Red Hat Enterprise Linux 7 | gstreamer1-plugins-bad-free | Fix deferred | ||
| Red Hat Enterprise Linux 7 | gstreamer-plugins-bad-free | Fix deferred | ||
| Red Hat Enterprise Linux 8 | gstreamer1-plugins-bad-free | Fix deferred | ||
| Red Hat Enterprise Linux 9 | gstreamer1-plugins-bad-free | Fix deferred |
Показывать по
Дополнительная информация
Статус:
5.3 Medium
CVSS3
Связанные уязвимости
Multiple out-of-bounds read vulnerabilities were found in GStreamer's pcapparse element. Malformed PCAP records can trigger reads beyond buffer boundaries during IPv4/TCP header parsing. This element is primarily used in debugging pipelines, limiting real-world exposure. A local attacker could trick a user into processing a specially crafted PCAP file, potentially leading to a crash or information disclosure.
Multiple out-of-bounds read vulnerabilities were found in GStreamer's pcapparse element. Malformed PCAP records can trigger reads beyond buffer boundaries during IPv4/TCP header parsing. This element is primarily used in debugging pipelines, limiting real-world exposure. A local attacker could trick a user into processing a specially crafted PCAP file, potentially leading to a crash or information disclosure.
Multiple out-of-bounds read vulnerabilities were found in GStreamer's ...
Multiple out-of-bounds read vulnerabilities were found in GStreamer's pcapparse element. Malformed PCAP records can trigger reads beyond buffer boundaries during IPv4/TCP header parsing. This element is primarily used in debugging pipelines, limiting real-world exposure. A local attacker could trick a user into processing a specially crafted PCAP file, potentially leading to a crash or information disclosure.
5.3 Medium
CVSS3