CVE-2009-0386: Buffer Overflow
Heap-based buffer overflow in the qtdemuxparsesamples function in gst/qtdemux/qtdemux.c in GStreamer Good Plug-ins (aka gst-plugins-good) 0.10.9 through 0.10.11 might allow remote attackers to execute arbitrary code via crafted Composition Time To Sample (ctts) atom data in a malformed QuickTime media .mov file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0386?
CVE-2009-0386 is classified as a critical vulnerability due to the potential for remote code execution.
How do I fix CVE-2009-0386?
To fix CVE-2009-0386, you should upgrade to GStreamer Good Plug-ins version 0.10.12 or later.
Which versions of GStreamer are affected by CVE-2009-0386?
CVE-2009-0386 affects GStreamer Good Plug-ins versions 0.10.9, 0.10.10, and 0.10.11.
What type of attack does CVE-2009-0386 involve?
CVE-2009-0386 involves a heap-based buffer overflow that can be exploited by sending specially crafted QuickTime files.
Can CVE-2009-0386 be exploited remotely?
Yes, CVE-2009-0386 can be exploited remotely, allowing attackers to execute arbitrary code on the affected system.