CVE-2009-0397
Heap-based buffer overflow in the qtdemux_parse_samples function in gst/qtdemux/qtdemux.c in GStreamer Good Plug-ins (aka gst-plugins-good) 0.10.9 through 0.10.11, and GStreamer Plug-ins (aka gstreamer-plugins) 0.8.5, might allow remote attackers to execute arbitrary code via crafted Time-to-sample (aka stts) atom data in a malformed QuickTime media .mov file.
- Affected products
- Gstreamer Good Plug-Ins, Gstreamer Plug-Ins, Apple Quicktime, Red Hat, Gstreamer0.10-Plugins-Bad
- Gstreamer Good Plug-ins
- = 0.10.9, 0.10.10, 0.10.11
- Gstreamer Plug-ins
- = 0.8.5
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- EPSS
- 7.2% (94th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2009-02-03
CVE-2009-0397 at NVD
No indexed exploits for CVE-2009-0397 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2009-0397 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.