Integer overflow in the gst_vorbis_tag_add_coverart function (gst-libs/gst/tag/gstvorbistag.c) in vorbistag in gst-plugins-base (aka gstreamer-plugins-base) before 0.10.23 in GStreamer allows context-dependent attackers to execute arbitrary code via a crafted COVERART tag that is converted from a base64 representation, which triggers a heap-based buffer overflow.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade gstreamer-plugins-base-develUpgrade gstreamer-plugins-base | Dec 1, 2016 | Mar 14, 2009 |
| Gentoo Linux | — | Upgrade media-libs/gst-plugins-good.Upgrade media-libs/gst-plugins-base.Upgrade media-plugins/gst-plugins-libpng. | Oct 30, 2017 | Mar 14, 2009 |
| Oracle_linux | — | Upgrade gstreamer-plugins-base-develUpgrade gstreamer-plugins-base | Oct 16, 2024 | Mar 14, 2009 |
| Suse | — | Upgrade libgstinterfaces-0_10-0-32bitUpgrade libgstapp-0_10-0Upgrade libgstapp-0_10-0-x86Upgrade libgstapp-0_10-0-32bitUpgrade gstreamer-0_10-plugins-baseUpgrade gstreamer-0_10-plugins-base-langUpgrade gstreamer-0_10-plugins-base-x86Upgrade gstreamer-0_10-plugins-base-develUpgrade gstreamer-0_10-plugins-base-32bitUpgrade libgstinterfaces-0_10-0-x86Upgrade libgstinterfaces-0_10-0Upgrade gstreamer-0_10-plugins-base-doc | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade gstreamer0.10-plugins-base | Nov 8, 2024 | Mar 14, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub