CVE-2009-0586
gstreamer-plugins-base: integer overflow in gst_vorbis_tag_add_coverart()
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Integer overflow in the gst_vorbis_tag_add_coverart function (gst-libs/gst/tag/gstvorbistag.c) in vorbistag in gst-plugins-base (aka gstreamer-plugins-base) before 0.10.23 in GStreamer allows context-dependent attackers to execute arbitrary code via a crafted COVERART tag that is converted from a base64 representation, which triggers a heap-based buffer overflow.
Un desbordamiento de enteros en la función gst_vorbis_tag_add_coverart (archivo gst-libs/gst/tag/gstvorbistag.c) en vorbistag en gst-plugins-base (se conoce como gstreamer-plugins-base) anterior a versión 0.10.23 en GStreamer, permite a los atacantes dependiendo del contexto ejecutar código arbitrario por medio de una etiqueta COVERART diseñada que es convertida desde una representación base64, lo que desencadena un desbordamiento de búfer en la región heap de la memoria.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-02-13 CVE Reserved
- 2009-03-14 CVE Published
- 2024-08-07 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-190: Integer Overflow or Wraparound
CAPEC
References (17)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/34335 | Not Applicable | |
http://secunia.com/advisories/34350 | Not Applicable | |
http://secunia.com/advisories/35777 | Not Applicable | |
http://www.ocert.org/advisories/ocert-2008-015.html | Third Party Advisory | |
http://www.securityfocus.com/archive/1/501712/100/0/threaded | Mailing List | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/49274 | Third Party Advisory | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9694 | Signature |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.html | 2023-02-13 | |
http://security.gentoo.org/glsa/glsa-200907-11.xml | 2023-02-13 | |
http://www.mandriva.com/security/advisories?name=MDVSA-2009:085 | 2023-02-13 | |
http://www.ubuntu.com/usn/USN-735-1 | 2023-02-13 | |
https://access.redhat.com/security/cve/CVE-2009-0586 | 2009-04-06 | |
https://bugzilla.redhat.com/show_bug.cgi?id=488208 | 2009-04-06 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Gstreamer Project Search vendor "Gstreamer Project" | Gstreamer Search vendor "Gstreamer Project" for product "Gstreamer" | < 0.10.23 Search vendor "Gstreamer Project" for product "Gstreamer" and version " < 0.10.23" | - |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 8.10 Search vendor "Canonical" for product "Ubuntu Linux" and version "8.10" | - |
Affected
|