Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23577
HistoryApr 10, 2020 - 12:31 a.m.

Arbitrary Code Execution

2020-04-1000:31:05
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

EPSS

0.437

Percentile

97.4%

gstreamer-plugins-good is vulnerable to arbitrary code execution. The vulnerability exists as multiple heap buffer overflows and an array indexing error were found in the GStreamer’s QuickTime media file format decoding plugin. An attacker could create a carefully-crafted QuickTime media .mov file that would cause an application using GStreamer to crash or, potentially, execute arbitrary code if played by a victim.

References