Количество 16
Количество 16
CVE-2026-53705
A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. The WavPack library then writes decoded audio samples far beyond the allocated buffer, resulting in heap memory corruption. This affects both 32-bit and 64-bit systems since the arithmetic is performed in 32-bit integers before promotion to the allocation size type. A remote attacker could use this flaw to crash an application or potentially execute arbitrary code by convincing a user to open a malicious WavPack audio file.
CVE-2026-53705
A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. The WavPack library then writes decoded audio samples far beyond the allocated buffer, resulting in heap memory corruption. This affects both 32-bit and 64-bit systems since the arithmetic is performed in 32-bit integers before promotion to the allocation size type. A remote attacker could use this flaw to crash an application or potentially execute arbitrary code by convincing a user to open a malicious WavPack audio file.
CVE-2026-53705
A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. The WavPack library then writes decoded audio samples far beyond the allocated buffer, resulting in heap memory corruption. This affects both 32-bit and 64-bit systems since the arithmetic is performed in 32-bit integers before promotion to the allocation size type. A remote attacker could use this flaw to crash an application or potentially execute arbitrary code by convincing a user to open a malicious WavPack audio file.
CVE-2026-53705
A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-g ...
openSUSE-SU-2026:21240-1
Security update for gstreamer-plugins-good
SUSE-SU-2026:2844-1
Security update for gstreamer-plugins-good
SUSE-SU-2026:2843-1
Security update for gstreamer-plugins-good
SUSE-SU-2026:2842-1
Security update for gstreamer-plugins-good
RLSA-2026:37129
Important: gstreamer1-plugins-good security update
RLSA-2026:36774
Important: gstreamer1-plugins-good security update
RLSA-2026:36675
Important: gstreamer1-plugins-good security update
GHSA-rc6x-6x52-9whj
A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. The WavPack library then writes decoded audio samples far beyond the allocated buffer, resulting in heap memory corruption. This affects both 32-bit and 64-bit systems since the arithmetic is performed in 32-bit integers before promotion to the allocation size type. A remote attacker could use this flaw to crash an application or potentially execute arbitrary code by convincing a user to open a malicious WavPack audio file.
ELSA-2026-37129
ELSA-2026-37129: gstreamer1-plugins-good security update (IMPORTANT)
ELSA-2026-36774
ELSA-2026-36774: gstreamer1-plugins-good security update (IMPORTANT)
ELSA-2026-36675
ELSA-2026-36675: gstreamer1-plugins-good security update (IMPORTANT)
SUSE-SU-2026:2727-1
Security update for gstreamer-plugins-good
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-53705 A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. The WavPack library then writes decoded audio samples far beyond the allocated buffer, resulting in heap memory corruption. This affects both 32-bit and 64-bit systems since the arithmetic is performed in 32-bit integers before promotion to the allocation size type. A remote attacker could use this flaw to crash an application or potentially execute arbitrary code by convincing a user to open a malicious WavPack audio file. | CVSS3: 7.6 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-53705 A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. The WavPack library then writes decoded audio samples far beyond the allocated buffer, resulting in heap memory corruption. This affects both 32-bit and 64-bit systems since the arithmetic is performed in 32-bit integers before promotion to the allocation size type. A remote attacker could use this flaw to crash an application or potentially execute arbitrary code by convincing a user to open a malicious WavPack audio file. | CVSS3: 7.6 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-53705 A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. The WavPack library then writes decoded audio samples far beyond the allocated buffer, resulting in heap memory corruption. This affects both 32-bit and 64-bit systems since the arithmetic is performed in 32-bit integers before promotion to the allocation size type. A remote attacker could use this flaw to crash an application or potentially execute arbitrary code by convincing a user to open a malicious WavPack audio file. | CVSS3: 7.6 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-53705 A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-g ... | CVSS3: 7.6 | 0% Низкий | около 2 месяцев назад | |
openSUSE-SU-2026:21240-1 Security update for gstreamer-plugins-good | 0% Низкий | 26 дней назад | ||
SUSE-SU-2026:2844-1 Security update for gstreamer-plugins-good | 0% Низкий | 21 день назад | ||
SUSE-SU-2026:2843-1 Security update for gstreamer-plugins-good | 0% Низкий | 21 день назад | ||
SUSE-SU-2026:2842-1 Security update for gstreamer-plugins-good | 0% Низкий | 21 день назад | ||
RLSA-2026:37129 Important: gstreamer1-plugins-good security update | 0% Низкий | 21 день назад | ||
RLSA-2026:36774 Important: gstreamer1-plugins-good security update | 0% Низкий | 23 дня назад | ||
RLSA-2026:36675 Important: gstreamer1-plugins-good security update | 0% Низкий | 21 день назад | ||
GHSA-rc6x-6x52-9whj A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. The WavPack library then writes decoded audio samples far beyond the allocated buffer, resulting in heap memory corruption. This affects both 32-bit and 64-bit systems since the arithmetic is performed in 32-bit integers before promotion to the allocation size type. A remote attacker could use this flaw to crash an application or potentially execute arbitrary code by convincing a user to open a malicious WavPack audio file. | CVSS3: 7.6 | 0% Низкий | около 2 месяцев назад | |
ELSA-2026-37129 ELSA-2026-37129: gstreamer1-plugins-good security update (IMPORTANT) | 23 дня назад | |||
ELSA-2026-36774 ELSA-2026-36774: gstreamer1-plugins-good security update (IMPORTANT) | 24 дня назад | |||
ELSA-2026-36675 ELSA-2026-36675: gstreamer1-plugins-good security update (IMPORTANT) | 16 дней назад | |||
SUSE-SU-2026:2727-1 Security update for gstreamer-plugins-good | 29 дней назад |
Уязвимостей на страницу