gst-plugins-base: arbitrary code execution
| Package(s): | gst-plugins-base0.10 |
CVE #(s): | CVE-2009-0586
|
| Created: | March 17, 2009 |
Updated: | July 13, 2009 |
| Description: |
From the Ubuntu advisory: It was discovered that the Base64 decoding functions in GStreamer Base
Plugins did not properly handle large images in Vorbis file tags. If a user
were tricked into opening a specially crafted Vorbis file, an attacker
could possibly execute arbitrary code with user privileges. |
| Alerts: |
| Gentoo |
200907-11 |
gst-plugins-good |
2009-07-12 |
| SuSE |
SUSE-SR:2009:009 |
openswan/strongswan, clamav, gstreamer-0_10-plugins-base, gnome-panel, postgresql, acroread_ja, ghostscript-devel, xine-devel/libxine-devel, moodle, gnutls, udev |
2009-04-21 |
| CentOS |
CESA-2009:0352 |
gstreamer-plugins-base |
2009-04-08 |
| Red Hat |
RHSA-2009:0352-01 |
gstreamer-plugins-base |
2009-04-06 |
| Mandriva |
MDVSA-2009:085 |
gstreamer0.10-plugins-base |
2009-04-02 |
| Ubuntu |
USN-735-1 |
gst-plugins-base0.10 |
2009-03-16 |
|