Heap-based buffer overflow in gstreamer - CVE-2019-9928
Published: June 25, 2020
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the the RTSP connection parser when processing a crafted response from a server. A remote attacker can trick the victim to connect to a malicious RTSP server, trigger heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Gentoo Linux
Opensuse
openEuler
gst-plugins-base (Alpine package)
gstreamer1-plugins-base
gstreamer1-plugins-base-debuginfo
gstreamer1-plugins-base-debugsource
gstreamer1-plugins-base-devel
gstreamer1-plugins-base-help
How to mitigate CVE-2019-9928
gst-plugins-base (Alpine package) - update to 1.14.4-r1
gstreamer1-plugins-base - update to 1.16.2-1
gstreamer1-plugins-base-debuginfo - update to 1.16.2-1
gstreamer1-plugins-base-debugsource - update to 1.16.2-1
gstreamer1-plugins-base-devel - update to 1.16.2-1
gstreamer1-plugins-base-help - update to 1.16.2-1
External References
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00078.html
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00082.html
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00049.html
- https://gstreamer.freedesktop.org/security/
- https://gstreamer.freedesktop.org/security/sa-2019-0001.html
- https://lists.debian.org/debian-lts-announce/2019/04/msg00030.html
- https://lists.debian.org/debian-lts-announce/2019/04/msg00031.html
- https://seclists.org/bugtraq/2019/Apr/39
- https://security.gentoo.org/glsa/202003-33
- https://usn.ubuntu.com/3958-1/
- https://www.debian.org/security/2019/dsa-4437
Related Security Bulletins
- Remote code execution in GStreamer
- OpenSUSE Linux update for gstreamer-plugins-base
- OpenSUSE Linux update for gstreamer-0_10-plugins-base
- OpenSUSE Linux update for gstreamer-plugins-base
- Heap-based buffer overflow in gst-plugins-base (Alpine package)
- Gentoo update for GStreamer Base Plugins
- openEuler 20.03 LTS update for gstreamer1-plugins-base-1.14.4-3