7.5
CVSSv2

CVE-2009-0586

Published: 14/03/2009 Updated: 13/02/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Integer overflow in the gst_vorbis_tag_add_coverart function (gst-libs/gst/tag/gstvorbistag.c) in vorbistag in gst-plugins-base (aka gstreamer-plugins-base) prior to 0.10.23 in GStreamer allows context-dependent malicious users to execute arbitrary code via a crafted COVERART tag that is converted from a base64 representation, which triggers a heap-based buffer overflow.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gstreamer project gstreamer

canonical ubuntu linux 8.10

Vendor Advisories

Synopsis Moderate: gstreamer-plugins-base security update Type/Severity Security Advisory: Moderate Topic Updated gstreamer-plugins-base packages that fix a security issue are nowavailable for Red Hat Enterprise Linux 5This update has been rated as having moderate security impact by the RedHat Security Res ...
It was discovered that the Base64 decoding functions in GStreamer Base Plugins did not properly handle large images in Vorbis file tags If a user were tricked into opening a specially crafted Vorbis file, an attacker could possibly execute arbitrary code with user privileges ...