See how gstreamer project compares to other vendors in security performance
GStreamer before 1.18.4 might access already-freed memory in error code paths when demuxing certain malformed Matroska files.
GStreamer before 1.18.4 may perform an out-of-bounds read when handling certain ID3v2 tags.
GStreamer before 1.18.4 might cause heap corruption when parsing certain malformed Matroska files.
An exploitable denial of service vulnerability exists in the GstRTSPAuth functionality of GStreamer/gst-rtsp-server 1.14.5. A specially crafted RTSP setup request can cause a null pointer deference resulting in denial-of-service. An attacker can send a malicious packet to trigger this vulnerability.
The gstasfdemuxprocessextstreamprops function in gst/asfdemux/gstasfdemux.c in gst-plugins-ugly in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (invalid memory read and crash) via vectors related to the number of languages in a video file.
The gstasfdemuxprocessextcontentdesc function in gst/asfdemux/gstasfdemux.c in gst-plugins-ugly in GStreamer allows remote attackers to cause a denial of service (out-of-bounds heap read) via vectors involving extended content descriptors.
An invalid memory read was found in gstavidemuxparsencdt.
Upstream bug:
https://bugzilla.gnome.org/showbug.cgi?id=777532
Upstream patch:
https://github.com/GStreamer/gst-plugins-good/commit/4f47835
CVE assignment:
http://seclists.org/oss-sec/2017/q1/284
Invalid memory read and possible buffer overflows were found in PSM parser.
Upstream bug:
https://bugzilla.gnome.org/showbug.cgi?id=777957
Upstream patch:
https://github.com/GStreamer/gst-plugins-bad/commit/948b87bf1514de
CVE assignment:
http://seclists.org/oss-sec/2017/q1/284
A use-after-free vulnerability was found in gstminiobjectunref / gsttaglistunref / gstmxfdemuxupdateessencetracks.
Upstream bug:
https://bugzilla.gnome.org/showbug.cgi?id=777503
Upstream patch:
https://github.com/GStreamer/gst-plugins-bad/commit/08723e6
CVE assignment:
http://seclists.org/oss-sec/2017/q1/284
A floating point exception was found in gstriffcreateaudiocaps.
Upstream bug:
https://bugzilla.gnome.org/showbug.cgi?id=777525
Upstream patch:
https://github.com/GStreamer/gst-plugins-base/commit/5d505d108800cef210f67dcfed2801ba36beac2a
CVE assignment:
http://seclists.org/oss-sec/2017/q1/284
An out-of-bounds read in gstdatetimenewfromiso8601string() was found that can be triggered by malformed datetime string.
Upstream bug:
https://bugzilla.gnome.org/showbug.cgi?id=777263
Upstream patch:
https://github.com/GStreamer/gstreamer/commit/9398b7f1a75b38844ae7050b5a7967e4cdebe24f
CVE assignment:
http://seclists.org/oss-sec/2017/q1/284
An endless recursion leading to a stack overflow in gstriffcreateaudiocaps was found.
Upstream bug:
https://bugzilla.gnome.org/showbug.cgi?id=777265
Upstream patch:
https://github.com/GStreamer/gst-plugins-base/commit/ef55c8a
CVE assignment:
http://seclists.org/oss-sec/2017/q1/284
An out-of-bounds heap read was found in qtdemuxparsesamples that can be triggered by specially crafted file.
Upstream bug:
https://bugzilla.gnome.org/showbug.cgi?id=777469
Upstream patches:
https://github.com/GStreamer/gst-plugins-good/commit/99d5d75 https://github.com/GStreamer/gst-plugins-good/commit/1ffef8b
CVE assignment:
http://seclists.org/oss-sec/2017/q1/284
An out-of-bounds heap read in htmlcontexthandleelement was found.
Upstream bug:
https://bugzilla.gnome.org/showbug.cgi?id=777502
Upstream patch:
https://github.com/GStreamer/gst-plugins-base/commit/d894c19
CVE assignment:
http://seclists.org/oss-sec/2017/q1/284
A floating point exception was found in gstriffcreateaudiocaps that can be triggered by specially crafted file.
Upstream bug:
https://bugzilla.gnome.org/showbug.cgi?id=777262
Upstream patch:
https://github.com/GStreamer/gst-plugins-base/commit/81d3ba3fa212bb25fe2ac661993887c4b69af6f1
CVE assignment:
http://seclists.org/oss-sec/2017/q1/284
An out-of-bounds heap read was found gstavidemuxparsencdt.
Upstream bug:
https://bugzilla.gnome.org/showbug.cgi?id=777500
Upstream patch:
https://github.com/GStreamer/gst-plugins-good/commit/32d9f3c
CVE assignment:
http://seclists.org/oss-sec/2017/q1/284
Integer overflow in the gstvorbistagaddcoverart function (gst-libs/gst/tag/gstvorbistag.c) in vorbistag in gst-plugins-base (aka gstreamer-plugins-base) before 0.10.23 in GStreamer allows context-dependent attackers to execute arbitrary code via a crafted COVERART tag that is converted from a base64 representation, which triggers a heap-based buffer overflow.
Integer overflow in the vmnc decoder in the gstreamer allows remote attackers to cause a denial of service (crash) via large width and height values, which triggers a buffer overflow.
The ROM mappings in the NSF decoder in gstreamer 0.10.x allow remote attackers to cause a denial of service (out-of-bounds read or write) and possibly execute arbitrary code via a crafted NSF music file.
An out-of-bounds read in qtdemuxtagaddstrfull was found that can be triggered by specially crafted file.
Upstream bug:
https://bugzilla.gnome.org/showbug.cgi?id=775451
Upstream patch:
https://github.com/GStreamer/gst-plugins-good/commit/d0949baf3dadea6021d54abef6802fed5a06af75
CVE assignment:
http://seclists.org/oss-sec/2017/q1/284
A missing initialization of allocated heap memory for render canvas leads to information leak.
CVE assignment:
http://seclists.org/oss-sec/2016/q4/462
External References:
https://scarybeastsecurity.blogspot.sk/2016/11/0day-poc-risky-design-decisions-in.html
An invalid memory read in gstaacparsesinksetcaps was found that can be triggered by specially crafted file.
Upstream bug:
https://bugzilla.gnome.org/showbug.cgi?id=775450
Upstream patch:
https://github.com/GStreamer/gst-plugins-good/commit/87a2c140ca54c5128093377e9b25a5c24b346727
CVE assignment:
http://seclists.org/oss-sec/2017/q1/284
GStreamer is a library for constructing graphs of media-handling components. A stack-buffer overflow has been detected in the vorbishandleidentificationpacket function within gstvorbisdec.c. The position array is a stack-allocated buffer of size 64. If vd->vi.channels exceeds 64, the for loop will write beyond the boundaries of the position array. The value written will always be GSTAUDIOCHANNELPOSITIONNONE. This vulnerability allows someone to overwrite the EIP address allocated in the stack. Additionally, this bug can overwrite the GstAudioInfo info structure. This vulnerability is fixed in 1.24.10.
GStreamer is a library for constructing graphs of media-handling components. The program attempts to reallocate the memory pointed to by stream->samples to accommodate stream->nsamples + samplescount elements of type QtDemuxSample. The problem is that samplescount is read from the input file. And if this value is big enough, this can lead to an integer overflow during the addition. As a consequence, gtryrenew might allocate memory for a significantly smaller number of elements than intended. Following this, the program iterates through samplescount elements and attempts to write samplescount number of elements, potentially exceeding the actual allocated memory size and causing an OOB-write. This vulnerability is fixed in 1.24.10.
GStreamer is a library for constructing graphs of media-handling components. An uninitialized stack variable vulnerability has been identified in the gstmatroskademuxaddwvpkheader function within matroska-demux.c. When size < 4, the program calls gstbufferunmap with an uninitialized map variable. Then, in the gstmemoryunmap function, the program will attempt to unmap the buffer using the uninitialized map variable, causing a function pointer hijack, as it will jump to mem->allocator->memunmapfull or mem->allocator->memunmap. This vulnerability could allow an attacker to hijack the execution flow, potentially leading to code execution. This vulnerability is fixed in 1.24.10.
GStreamer is a library for constructing graphs of media-handling components. An OOB-write vulnerability has been identified in the gstssaparseremoveoverridecodes function of the gstssaparse.c file. This function is responsible for parsing and removing SSA (SubStation Alpha) style override codes, which are enclosed in curly brackets ({}). The issue arises when a closing curly bracket "}" appears before an opening curly bracket "{" in the input string. In this case, memmove() incorrectly duplicates a substring. With each successive loop iteration, the size passed to memmove() becomes progressively larger (strlen(end+1)), leading to a write beyond the allocated memory bounds. This vulnerability is fixed in 1.24.10.
GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been discovered in qtdemuxparsecontainer function within qtdemux.c. In the parent function qtdemuxparsenode, the value of length is not well checked. So, if length is big enough, it causes the pointer end to point beyond the boundaries of buffer. Subsequently, in the qtdemuxparsecontainer function, the while loop can trigger an OOB-read, accessing memory beyond the bounds of buf. This vulnerability can result in reading up to 4GB of process memory or potentially causing a segmentation fault (SEGV) when accessing invalid memory. This vulnerability is fixed in 1.24.10.
GStreamer is a library for constructing graphs of media-handling components. An out-of-bounds write vulnerability was identified in the converttos3341a function in isomp4/qtdemux.c. The vulnerability arises due to a discrepancy between the size of memory allocated to the storage array and the loop condition i 2 < ccpairsize. Specifically, when ccpairsize is even, the allocated size in storage does not match the loop's expected bounds, resulting in an out-of-bounds write. This bug allows for the overwriting of up to 3 bytes beyond the allocated bounds of the storage array. This vulnerability is fixed in 1.24.10.
GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference has been discovered in the id3v2readsynchuint function, located in id3v2.c. If id3v2readsynchuint is called with a null work->hdr.framedata, the pointer guint8 data is accessed without validation, resulting in a null pointer dereference. This vulnerability can result in a Denial of Service (DoS) by triggering a segmentation fault (SEGV). This vulnerability is fixed in 1.24.10.
GStreamer is a library for constructing graphs of media-handling components. An integer underflow has been detected in qtdemuxparsetrak function within qtdemux.c. During the strf parsing case, the subtraction size -= 40 can lead to a negative integer overflow if it is less than 40. If this happens, the subsequent call to gstbufferfill will invoke memcpy with a large tocopy size, resulting in an OOB-read. This vulnerability is fixed in 1.24.10.