CVE-2019-9928 PUBLISHED

GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection parser via a crafted response from a server, potentially allowing remote code execution.

EPSS 17.34% · 95.0th percentile

Risk Scores

EPSS Score
17.34%
95.0th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSgst-plugins-base0.100, 0.10.36-2, 0.10.36-2ubuntu0.1
Ubuntu:18.04:LTSgst-plugins-base1.01.12.3-1, 0, 1.12.4-1
Ubuntu:16.04:LTSgst-plugins-base1.01.6.2-1ubuntu1, 1.7.90-1ubuntu1, 1.6.0-1ubuntu1

Timeline

References

Open in Interactive Console →