Количество 13
Количество 13
CVE-2026-73434
A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_riff_vprp_video_field_desc entries is calculated by dividing the remaining buffer size by the attacker-controlled vprp->fields value, rather than by sizeof(gst_riff_vprp_video_field_desc). This can cause the parser to treat more field descriptors as available than fit in the input buffer, resulting in out-of-bounds reads. Processing a crafted AVI via playbin/decodebin can crash the application (denial of service). Fixed upstream in gst-plugins-good 1.28.6 (GStreamer-SA-2026-0072).
CVE-2026-73434
A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_riff_vprp_video_field_desc entries is calculated by dividing the remaining buffer size by the attacker-controlled vprp->fields value, rather than by sizeof(gst_riff_vprp_video_field_desc). This can cause the parser to treat more field descriptors as available than fit in the input buffer, resulting in out-of-bounds reads. Processing a crafted AVI via playbin/decodebin can crash the application (denial of service). Fixed upstream in gst-plugins-good 1.28.6 (GStreamer-SA-2026-0072).
CVE-2026-73434
A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_riff_vprp_video_field_desc entries is calculated by dividing the remaining buffer size by the attacker-controlled vprp->fields value, rather than by sizeof(gst_riff_vprp_video_field_desc). This can cause the parser to treat more field descriptors as available than fit in the input buffer, resulting in out-of-bounds reads. Processing a crafted AVI via playbin/decodebin can crash the application (denial of service). Fixed upstream in gst-plugins-good 1.28.6 (GStreamer-SA-2026-0072).
CVE-2026-73434
A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_ ...
ROS-20260922-80-0005
Уязвимость gstreamer1-plugins-good
ROS-20260922-73-0005
Уязвимость gstreamer1-plugins-good
GHSA-wfhj-v65x-vjp5
A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_riff_vprp_video_field_desc entries is calculated by dividing the remaining buffer size by the attacker-controlled vprp->fields value, rather than by sizeof(gst_riff_vprp_video_field_desc). This can cause the parser to treat more field descriptors as available than fit in the input buffer, resulting in out-of-bounds reads. Processing a crafted AVI via playbin/decodebin can crash the application (denial of service). Fixed upstream in gst-plugins-good 1.28.6 (GStreamer-SA-2026-0072).
RLSA-2026:55436
Moderate: gstreamer1-plugins-good security update
RLSA-2026:55434
Moderate: gstreamer1-plugins-good security update
ELSA-2026-55436
ELSA-2026-55436: gstreamer1-plugins-good security update (MODERATE)
ELSA-2026-55434
ELSA-2026-55434: gstreamer1-plugins-good security update (MODERATE)
RLSA-2026:56966
Moderate: gstreamer1-plugins-good security update
ELSA-2026-56966
ELSA-2026-56966: gstreamer1-plugins-good security update (MODERATE)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-73434 A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_riff_vprp_video_field_desc entries is calculated by dividing the remaining buffer size by the attacker-controlled vprp->fields value, rather than by sizeof(gst_riff_vprp_video_field_desc). This can cause the parser to treat more field descriptors as available than fit in the input buffer, resulting in out-of-bounds reads. Processing a crafted AVI via playbin/decodebin can crash the application (denial of service). Fixed upstream in gst-plugins-good 1.28.6 (GStreamer-SA-2026-0072). | CVSS3: 6.1 | 0% Низкий | около 1 месяца назад | |
CVE-2026-73434 A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_riff_vprp_video_field_desc entries is calculated by dividing the remaining buffer size by the attacker-controlled vprp->fields value, rather than by sizeof(gst_riff_vprp_video_field_desc). This can cause the parser to treat more field descriptors as available than fit in the input buffer, resulting in out-of-bounds reads. Processing a crafted AVI via playbin/decodebin can crash the application (denial of service). Fixed upstream in gst-plugins-good 1.28.6 (GStreamer-SA-2026-0072). | CVSS3: 6.1 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-73434 A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_riff_vprp_video_field_desc entries is calculated by dividing the remaining buffer size by the attacker-controlled vprp->fields value, rather than by sizeof(gst_riff_vprp_video_field_desc). This can cause the parser to treat more field descriptors as available than fit in the input buffer, resulting in out-of-bounds reads. Processing a crafted AVI via playbin/decodebin can crash the application (denial of service). Fixed upstream in gst-plugins-good 1.28.6 (GStreamer-SA-2026-0072). | CVSS3: 6.1 | 0% Низкий | около 1 месяца назад | |
CVE-2026-73434 A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_ ... | CVSS3: 6.1 | 0% Низкий | около 1 месяца назад | |
ROS-20260922-80-0005 Уязвимость gstreamer1-plugins-good | CVSS3: 6.1 | 0% Низкий | 3 дня назад | |
ROS-20260922-73-0005 Уязвимость gstreamer1-plugins-good | CVSS3: 6.1 | 0% Низкий | 3 дня назад | |
GHSA-wfhj-v65x-vjp5 A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_riff_vprp_video_field_desc entries is calculated by dividing the remaining buffer size by the attacker-controlled vprp->fields value, rather than by sizeof(gst_riff_vprp_video_field_desc). This can cause the parser to treat more field descriptors as available than fit in the input buffer, resulting in out-of-bounds reads. Processing a crafted AVI via playbin/decodebin can crash the application (denial of service). Fixed upstream in gst-plugins-good 1.28.6 (GStreamer-SA-2026-0072). | CVSS3: 7.1 | 0% Низкий | около 1 месяца назад | |
RLSA-2026:55436 Moderate: gstreamer1-plugins-good security update | около 1 месяца назад | |||
RLSA-2026:55434 Moderate: gstreamer1-plugins-good security update | около 1 месяца назад | |||
ELSA-2026-55436 ELSA-2026-55436: gstreamer1-plugins-good security update (MODERATE) | около 1 месяца назад | |||
ELSA-2026-55434 ELSA-2026-55434: gstreamer1-plugins-good security update (MODERATE) | около 1 месяца назад | |||
RLSA-2026:56966 Moderate: gstreamer1-plugins-good security update | около 1 месяца назад | |||
ELSA-2026-56966 ELSA-2026-56966: gstreamer1-plugins-good security update (MODERATE) | около 1 месяца назад |
Уязвимостей на страницу