VDB
CVE-2009-0397
CVE-2009-0397
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Heap-based buffer overflow in the qtdemux_parse_samples function in gst/qtdemux/qtdemux.c in GStreamer Good Plug-ins (aka gst-plugins-good) 0.10.9 through 0.10.11, and GStreamer Plug-ins (aka gstreamer-plugins) 0.8.5, might allow remote attackers to execute arbitrary code via crafted Time-to-sample (aka stts) atom data in a malformed QuickTime media .mov file.
EPSS 13.57% · 94.4th percentile
Risk Scores
CVSS 2.0
9.300000190734863
EPSS Score
13.57%
94.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| gstreamer | plug-ins | 0.8.5 |
| n/a | n/a | n/a |
| gstreamer | good_plug-ins | 0.10.9, 0.10.11, 0.10.10 |
Timeline
- Feb 3, 2009 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 2, 2022 CVE Updated
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 9, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- 33405 vdb
- 20090122 [TKADV2009-003] GStreamer Heap Overflow and Array Index out of Bounds Vulnerabilities mailing-list
- 34336 third-party-advisory
- 33815 third-party-advisory
- 35777 third-party-advisory
- http://trapkit.de/advisories/TKADV2009-003.txt url
- RHSA-2009:0271 vendor-advisory
- 33830 third-party-advisory
- GLSA-200907-11 vendor-advisory
- 33650 third-party-advisory
- ADV-2009-0225 vdb
- SUSE-SR:2009:005 vendor-advisory
- oval:org.mitre.oval:def:9942 vdb
- RHSA-2009:0270 vendor-advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=481267 url
- gstreamer-qtdemuxparse-bo(48555) vdb
- http://support.avaya.com/elmodocs2/security/ASA-2009-052.htm url
- USN-736-1 vendor-advisory
- http://gstreamer.freedesktop.org/releases/gst-plugins-good/0.10.12.html url
- [oss-security] 20090129 CVE Request -- (sort of urgent) gstreamer-plugins-good (repost) (more details about affected versions -- final version) mailing-list
…and 3 more