Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 9

Количество 9

github логотип

GHSA-hghw-p2mw-fvch

около 2 месяцев назад

A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file, the demuxer parses MDPR (media properties) chunks to configure audio streams. For audio stream header versions 4 and 5, the parser reads fields such as codec type, packet size, sample rate, channel count, and extra codec data length from fixed offsets within the chunk without first checking that the chunk contains enough data. If a malicious file provides an MDPR chunk that is too small to contain a complete audio stream header, the parser reads beyond the end of the buffer. This can cause the application to crash. In some cases, bytes read past the buffer boundary may be incorporated into stream metadata, which could result in limited information disclosure.

CVSS3: 7.1
EPSS: Низкий
ubuntu логотип

CVE-2026-53703

около 2 месяцев назад

A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file, the demuxer parses MDPR (media properties) chunks to configure audio streams. For audio stream header versions 4 and 5, the parser reads fields such as codec type, packet size, sample rate, channel count, and extra codec data length from fixed offsets within the chunk without first checking that the chunk contains enough data. If a malicious file provides an MDPR chunk that is too small to contain a complete audio stream header, the parser reads beyond the end of the buffer. This can cause the application to crash. In some cases, bytes read past the buffer boundary may be incorporated into stream metadata, which could result in limited information disclosure.

CVSS3: 7.1
EPSS: Низкий
redhat логотип

CVE-2026-53703

около 2 месяцев назад

A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file, the demuxer parses MDPR (media properties) chunks to configure audio streams. For audio stream header versions 4 and 5, the parser reads fields such as codec type, packet size, sample rate, channel count, and extra codec data length from fixed offsets within the chunk without first checking that the chunk contains enough data. If a malicious file provides an MDPR chunk that is too small to contain a complete audio stream header, the parser reads beyond the end of the buffer. This can cause the application to crash. In some cases, bytes read past the buffer boundary may be incorporated into stream metadata, which could result in limited information disclosure.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-53703

около 2 месяцев назад

A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file, the demuxer parses MDPR (media properties) chunks to configure audio streams. For audio stream header versions 4 and 5, the parser reads fields such as codec type, packet size, sample rate, channel count, and extra codec data length from fixed offsets within the chunk without first checking that the chunk contains enough data. If a malicious file provides an MDPR chunk that is too small to contain a complete audio stream header, the parser reads beyond the end of the buffer. This can cause the application to crash. In some cases, bytes read past the buffer boundary may be incorporated into stream metadata, which could result in limited information disclosure.

CVSS3: 7.1
EPSS: Низкий
debian логотип

CVE-2026-53703

около 2 месяцев назад

A vulnerability was found in the GStreamer RealMedia demuxer (gst-plug ...

CVSS3: 7.1
EPSS: Низкий
rocky логотип

RLSA-2026:36673

21 день назад

Moderate: gstreamer1-plugins-ugly-free security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-36673

16 дней назад

ELSA-2026-36673: gstreamer1-plugins-ugly-free security update (MODERATE)

EPSS: Низкий
rocky логотип

RLSA-2026:36674

21 день назад

Moderate: gstreamer1-plugins-ugly-free security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-36674

24 дня назад

ELSA-2026-36674: gstreamer1-plugins-ugly-free security update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-hghw-p2mw-fvch

A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file, the demuxer parses MDPR (media properties) chunks to configure audio streams. For audio stream header versions 4 and 5, the parser reads fields such as codec type, packet size, sample rate, channel count, and extra codec data length from fixed offsets within the chunk without first checking that the chunk contains enough data. If a malicious file provides an MDPR chunk that is too small to contain a complete audio stream header, the parser reads beyond the end of the buffer. This can cause the application to crash. In some cases, bytes read past the buffer boundary may be incorporated into stream metadata, which could result in limited information disclosure.

CVSS3: 7.1
0%
Низкий
около 2 месяцев назад
ubuntu логотип
CVE-2026-53703

A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file, the demuxer parses MDPR (media properties) chunks to configure audio streams. For audio stream header versions 4 and 5, the parser reads fields such as codec type, packet size, sample rate, channel count, and extra codec data length from fixed offsets within the chunk without first checking that the chunk contains enough data. If a malicious file provides an MDPR chunk that is too small to contain a complete audio stream header, the parser reads beyond the end of the buffer. This can cause the application to crash. In some cases, bytes read past the buffer boundary may be incorporated into stream metadata, which could result in limited information disclosure.

CVSS3: 7.1
0%
Низкий
около 2 месяцев назад
redhat логотип
CVE-2026-53703

A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file, the demuxer parses MDPR (media properties) chunks to configure audio streams. For audio stream header versions 4 and 5, the parser reads fields such as codec type, packet size, sample rate, channel count, and extra codec data length from fixed offsets within the chunk without first checking that the chunk contains enough data. If a malicious file provides an MDPR chunk that is too small to contain a complete audio stream header, the parser reads beyond the end of the buffer. This can cause the application to crash. In some cases, bytes read past the buffer boundary may be incorporated into stream metadata, which could result in limited information disclosure.

CVSS3: 7.1
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-53703

A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file, the demuxer parses MDPR (media properties) chunks to configure audio streams. For audio stream header versions 4 and 5, the parser reads fields such as codec type, packet size, sample rate, channel count, and extra codec data length from fixed offsets within the chunk without first checking that the chunk contains enough data. If a malicious file provides an MDPR chunk that is too small to contain a complete audio stream header, the parser reads beyond the end of the buffer. This can cause the application to crash. In some cases, bytes read past the buffer boundary may be incorporated into stream metadata, which could result in limited information disclosure.

CVSS3: 7.1
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-53703

A vulnerability was found in the GStreamer RealMedia demuxer (gst-plug ...

CVSS3: 7.1
0%
Низкий
около 2 месяцев назад
rocky логотип
RLSA-2026:36673

Moderate: gstreamer1-plugins-ugly-free security update

0%
Низкий
21 день назад
oracle-oval логотип
ELSA-2026-36673

ELSA-2026-36673: gstreamer1-plugins-ugly-free security update (MODERATE)

16 дней назад
rocky логотип
RLSA-2026:36674

Moderate: gstreamer1-plugins-ugly-free security update

21 день назад
oracle-oval логотип
ELSA-2026-36674

ELSA-2026-36674: gstreamer1-plugins-ugly-free security update (MODERATE)

24 дня назад

Уязвимостей на страницу