LWN.net Logo

gstreamer-plugins: arbitrary code execution

Package(s):gstreamer-plugins CVE #(s):CVE-2009-0398
Created:February 6, 2009 Updated:April 6, 2009
Description: An array indexing error was found in the GStreamer's QuickTime media file format decoding plug-in. An attacker could create a carefully-crafted QuickTime media .mov file that would cause an application using GStreamer to crash or, potentially, execute arbitrary code if played by a victim.
Alerts:
Mandriva MDVSA-2009:086 2009-04-03
Red Hat RHSA-2009:0269-01 2009-02-06
CentOS CESA-2009:0269 2009-02-06

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds