Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-9928

Опубликовано: 24 апр. 2019
Источник: ubuntu
Приоритет: high
EPSS Средний
CVSS2: 6.8
CVSS3: 8.8

Описание

GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection parser via a crafted response from a server, potentially allowing remote code execution.

РелизСтатусПримечание
bionic

DNE

cosmic

DNE

devel

DNE

disco

DNE

esm-apps/xenial

released

0.10.36-2ubuntu0.2
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was needs-triage]
precise/esm

DNE

trusty

ignored

end of standard support
trusty/esm

DNE

trusty was needs-triage
upstream

needs-triage

Показывать по

РелизСтатусПримечание
bionic

released

1.14.1-1ubuntu1~ubuntu18.04.2
cosmic

released

1.14.4-1ubuntu1.1
devel

not-affected

1.15.90-1
disco

not-affected

1.15.90-1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was needs-triage]
esm-infra/bionic

released

1.14.1-1ubuntu1~ubuntu18.04.2
esm-infra/xenial

released

1.8.3-1ubuntu0.3
precise/esm

DNE

trusty

ignored

end of standard support
trusty/esm

DNE

trusty was needs-triage

Показывать по

EPSS

Процентиль: 95%
0.17603
Средний

6.8 Medium

CVSS2

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
почти 7 лет назад

GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection parser via a crafted response from a server, potentially allowing remote code execution.

CVSS3: 8.8
nvd
почти 7 лет назад

GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection parser via a crafted response from a server, potentially allowing remote code execution.

CVSS3: 8.8
debian
почти 7 лет назад

GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP c ...

suse-cvrf
больше 5 лет назад

Security update for gstreamer-plugins-base

suse-cvrf
больше 6 лет назад

Security update for gstreamer-plugins-base

EPSS

Процентиль: 95%
0.17603
Средний

6.8 Medium

CVSS2

8.8 High

CVSS3