VDB
CVE-2009-0386
CVE-2009-0386
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Heap-based buffer overflow in the qtdemux_parse_samples function in gst/qtdemux/qtdemux.c in GStreamer Good Plug-ins (aka gst-plugins-good) 0.10.9 through 0.10.11 might allow remote attackers to execute arbitrary code via crafted Composition Time To Sample (ctts) atom data in a malformed QuickTime media .mov file.
EPSS 11.73% · 93.8th percentile
Risk Scores
CVSS 2.0
9.300000190734863
EPSS Score
11.73%
93.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| gstreamer | good_plug-ins | 0.10.9, 0.10.11, 0.10.10 |
Timeline
- Feb 2, 2009 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jun 22, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- 33405 vdb
- oval:org.mitre.oval:def:10306 vdb
- 20090122 [TKADV2009-003] GStreamer Heap Overflow and Array Index out of Bounds Vulnerabilities mailing-list
- 34336 third-party-advisory
- 33815 third-party-advisory
- 35777 third-party-advisory
- http://trapkit.de/advisories/TKADV2009-003.txt url
- RHSA-2009:0271 vendor-advisory
- GLSA-200907-11 vendor-advisory
- 33650 third-party-advisory
- ADV-2009-0225 vdb
- SUSE-SR:2009:005 vendor-advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=481267 url
- USN-736-1 vendor-advisory
- http://gstreamer.freedesktop.org/releases/gst-plugins-good/0.10.12.html url
- [oss-security] 20090129 CVE Request -- (sort of urgent) gstreamer-plugins-good (repost) (more details about affected versions -- final version) mailing-list
- http://cgit.freedesktop.org/gstreamer/gst-plugins-good/commit/?id=bdc20b9baf13564d9a061343416395f8f9a92b53 url
- MDVSA-2009:035 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2009-0386 advisory