REDHAT-BUG-1181404: Buffer Overflow
Sergey "Shnatsel" Davidoff reported a heap-based buffer overflow in Vala Gstreamer bindings in the Gst.MapInfo() function. Further details are available in the following Red Hat bug:
https://bugzilla.redhat.com/showbug.cgi?id=1177840
This issue was also reported via: https://bugzilla.gnome.org/showbug.cgi?id=678663
and fixed in the following commit:
https://git.gnome.org/browse/vala/commit/?id=3092537db65887e24a3d3e87a27caf9c5295e4f7
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1181404?
The severity of REDHAT-BUG-1181404 is considered high due to the heap-based buffer overflow vulnerability.
How do I fix REDHAT-BUG-1181404?
To fix REDHAT-BUG-1181404, you should update the affected GStreamer and GNOME Vala packages to their latest versions.
What software is affected by REDHAT-BUG-1181404?
REDHAT-BUG-1181404 affects GNOME Vala and GStreamer software implementations.
What causes the vulnerability in REDHAT-BUG-1181404?
The vulnerability in REDHAT-BUG-1181404 is caused by a heap-based buffer overflow in the Gst.MapInfo() function.
Is there a workaround for REDHAT-BUG-1181404?
A workaround for REDHAT-BUG-1181404 involves avoiding the use of the Gst.MapInfo() function until a patch is applied.