Heap-based buffer overflow in gstreamer - CVE-2019-9928

 

Heap-based buffer overflow in gstreamer - CVE-2019-9928

Published: June 25, 2020


Vulnerability identifier: #VU29256
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-9928
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error within the the RTSP connection parser when processing a crafted response from a server. A remote attacker can trick the victim to connect to a malicious RTSP server, trigger heap-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

gstreamer
Gentoo Linux
Opensuse
openEuler
gst-plugins-base (Alpine package)
gstreamer1-plugins-base
gstreamer1-plugins-base-debuginfo
gstreamer1-plugins-base-debugsource
gstreamer1-plugins-base-devel
gstreamer1-plugins-base-help

How to mitigate CVE-2019-9928

Install update from vendor's website.

gstreamer - update to 1.16.0
gst-plugins-base (Alpine package) - update to 1.14.4-r1
gstreamer1-plugins-base - update to 1.16.2-1
gstreamer1-plugins-base-debuginfo - update to 1.16.2-1
gstreamer1-plugins-base-debugsource - update to 1.16.2-1
gstreamer1-plugins-base-devel - update to 1.16.2-1
gstreamer1-plugins-base-help - update to 1.16.2-1

External References

Related Security Bulletins