6.8
CVSSv2

CVE-2009-1932

Published: 04/06/2009 Updated: 29/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple integer overflows in the (1) user_info_callback, (2) user_endrow_callback, and (3) gst_pngdec_task functions (ext/libpng/gstpngdec.c) in GStreamer Good Plug-ins (aka gst-plugins-good or gstreamer-plugins-good) 0.10.15 allow remote malicious users to cause a denial of service and possibly execute arbitrary code via a crafted PNG file, which triggers a buffer overflow.

Vulnerable Product Search on Vulmon Subscribe to Product

gstreamer good plug-ins 0.10.15

Vendor Advisories

Synopsis Moderate: gstreamer-plugins-good security update Type/Severity Security Advisory: Moderate Topic Updated gstreamer-plugins-good packages that fix multiple security issuesare now available for Red Hat Enterprise Linux 5This update has been rated as having moderate security impact by the RedHat Secu ...
Tielei Wang discovered that GStreamer Good Plugins did not correctly handle malformed PNG image files If a user were tricked into opening a crafted PNG image file with a GStreamer application, an attacker could cause a denial of service via application crash, or possibly execute arbitrary code with the privileges of the user invoking the program ...