Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23576
HistoryApr 10, 2020 - 12:31 a.m.

Arbitrary Code Execution

2020-04-1000:31:05
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

EPSS

0.134

Percentile

95.6%

gstreamer-plugins-good is vulnerable to arbitrary code execution. The vulnerability exists as multiple heap buffer overflows and an array indexing error were found in the GStreamer’s QuickTime media file format decoding plugin. An attacker could create a carefully-crafted QuickTime media .mov file that would cause an application using GStreamer to crash or, potentially, execute arbitrary code if played by a victim.

References