Description
Heap-based buffer overflow in the qtdemux_parse_samples function in gst/qtdemux/qtdemux.c in GStreamer Good Plug-ins (aka gst-plugins-good) 0.10.9 through 0.10.11, and GStreamer Plug-ins (aka gstreamer-plugins) 0.8.5, might allow remote attackers to execute arbitrary code via crafted Time-to-sample (aka stts) atom data in a malformed QuickTime media .mov file.Novell Bugzilla entry: 469336 SUSE Security Advisories:
- SUSE-SR:2009:005, published Mon, 02 Mar 2009 13:00:00 +0000
- SUSE-SR:2009:005 , published Mon, 02 Mar 2009 13:00:00 +0000
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| openSUSE 11.0 |
| SAT Patch Nr: 540 |
| openSUSE 11.0 |
| SAT Patch Nr: 540 |
| openSUSE 11.1 |
| SAT Patch Nr: 540 |
| openSUSE 11.1 |
| SAT Patch Nr: 540 |
| openSUSE 10.3 |
| |
| Novell Linux Desktop 9 for x86 Novell Linux Desktop 9 for x86_64 |
| sles9-nld. x86 sles9-nld. x86-64 YOU Patch Nr: 12355 |
