VDB
CVE-2009-1932
CVE-2009-1932
PUBLISHED
CVSS 6.800000190734863 MEDIUM
Multiple integer overflows in the (1) user_info_callback, (2) user_endrow_callback, and (3) gst_pngdec_task functions (ext/libpng/gstpngdec.c) in GStreamer Good Plug-ins (aka gst-plugins-good or gstreamer-plugins-good) 0.10.15 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted PNG file, which triggers a buffer overflow.
EPSS 8.31% · 92.4th percentile
Risk Scores
CVSS 2.0
6.800000190734863
EPSS Score
8.31%
92.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| gstreamer | good_plug-ins | 0.10.15 |
| n/a | n/a | n/a |
Timeline
- Jun 4, 2009 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- 35777 third-party-advisory
- 35583 third-party-advisory
- ADV-2009-1506 vdb
- DSA-1839 vendor-advisory
- GLSA-200907-11 vendor-advisory
- http://cgit.freedesktop.org/gstreamer/gst-plugins-good/commit/?id=d9544bcc44adcef769cbdf7f6453e140058a3adc url
- 35205 third-party-advisory
- 35172 vdb
- oval:org.mitre.oval:def:10798 vdb
- 35897 third-party-advisory
- 54827 vdb
- RHSA-2009:1123 vendor-advisory
- MDVSA-2009:130 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2009-1932 advisory