VDB
CVE-2009-0387
CVE-2009-0387
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Array index error in the qtdemux_parse_samples function in gst/qtdemux/qtdemux.c in GStreamer Good Plug-ins (aka gst-plugins-good) 0.10.9 through 0.10.11 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted Sync Sample (aka stss) atom data in a malformed QuickTime media .mov file, related to "mark keyframes."
EPSS 17.87% · 95.3th percentile
Risk Scores
CVSS 2.0
9.300000190734863
EPSS Score
17.87%
95.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| gstreamer | plug-ins | 0.8.5 |
| gstreamer | good_plug-ins | 0.10.9, 0.10.10, 0.10.11 |
Timeline
- Feb 2, 2009 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jun 22, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- 33405 vdb
- 20090122 [TKADV2009-003] GStreamer Heap Overflow and Array Index out of Bounds Vulnerabilities mailing-list
- 34336 third-party-advisory
- 33815 third-party-advisory
- 35777 third-party-advisory
- http://trapkit.de/advisories/TKADV2009-003.txt url
- RHSA-2009:0271 vendor-advisory
- GLSA-200907-11 vendor-advisory
- 33650 third-party-advisory
- ADV-2009-0225 vdb
- SUSE-SR:2009:005 vendor-advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=481267 url
- USN-736-1 vendor-advisory
- http://gstreamer.freedesktop.org/releases/gst-plugins-good/0.10.12.html url
- oval:org.mitre.oval:def:10611 vdb
- [oss-security] 20090129 CVE Request -- (sort of urgent) gstreamer-plugins-good (repost) (more details about affected versions -- final version) mailing-list
- http://cgit.freedesktop.org/gstreamer/gst-plugins-good/commit/?id=bdc20b9baf13564d9a061343416395f8f9a92b53 url
- MDVSA-2009:035 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2009-0387 advisory