Lucene search

K
cveMitreCVE-2009-0387
HistoryFeb 02, 2009 - 7:30 p.m.

CVE-2009-0387

2009-02-0219:30:00
CWE-119
mitre
web.nvd.nist.gov
50
cve-2009-0387
nvd
gstreamer
good plug-ins
denial of service
remote attack
arbitrary code
sync sample
atom data
quicktime
media file

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.5

Confidence

Low

EPSS

0.437

Percentile

97.4%

Array index error in the qtdemux_parse_samples function in gst/qtdemux/qtdemux.c in GStreamer Good Plug-ins (aka gst-plugins-good) 0.10.9 through 0.10.11 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted Sync Sample (aka stss) atom data in a malformed QuickTime media .mov file, related to “mark keyframes.”

Affected configurations

Nvd
Node
gstreamergood_plug-insMatch0.10.9
OR
gstreamergood_plug-insMatch0.10.10
OR
gstreamergood_plug-insMatch0.10.11
OR
gstreamerplug-insMatch0.8.5
VendorProductVersionCPE
gstreamergood_plug-ins0.10.9cpe:2.3:a:gstreamer:good_plug-ins:0.10.9:*:*:*:*:*:*:*
gstreamergood_plug-ins0.10.10cpe:2.3:a:gstreamer:good_plug-ins:0.10.10:*:*:*:*:*:*:*
gstreamergood_plug-ins0.10.11cpe:2.3:a:gstreamer:good_plug-ins:0.10.11:*:*:*:*:*:*:*
gstreamerplug-ins0.8.5cpe:2.3:a:gstreamer:plug-ins:0.8.5:*:*:*:*:*:*:*

References

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.5

Confidence

Low

EPSS

0.437

Percentile

97.4%