Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23578
HistoryApr 10, 2020 - 12:31 a.m.

Arbitrary Code Execution

2020-04-1000:31:06
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

EPSS

0.086

Percentile

94.5%

gstreamer-plugins-good is vulnerable to arbitrary code execution. The vulnerability exists through multiple heap buffer overflows and an array indexing error were found in the GStreamer’s QuickTime media file format decoding plugin. An attacker could create a carefully-crafted QuickTime media .mov file that would cause an application using GStreamer to crash or, potentially, execute arbitrary code if played by a victim.

References