Novell Home

CVE-2009-0586

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

CVE-2009-0586 at MITRE

Details

Integer overflow in the gst_vorbis_tag_add_coverart function (gst-libs/gst/tag/gstvorbistag.c) in vorbistag in gst-plugins-base (aka gstreamer-plugins-base) before 0.10.23 in GStreamer allows context-dependent attackers to execute arbitrary code via a crafted COVERART tag that is converted from a base64 representation, which triggers a heap-based buffer overflow.
Novell Bugzilla entry: 481479

SUSE Security Advisories:

Product(s) Fixed package version(s) References
openSUSE 11.1
  • gstreamer-0_10-plugins-base-debuginfo >= 0.10.21-2.21.2
  • gstreamer-0_10-plugins-base-debuginfo-32bit >= 0.10.21-2.21.2
  • gstreamer-0_10-plugins-base-debugsource >= 0.10.21-2.21.2
SAT Patch Nr: 741
openSUSE 11.1
  • gstreamer-0_10-plugins-base >= 0.10.21-2.21.2
  • gstreamer-0_10-plugins-base-32bit >= 0.10.21-2.21.2
  • gstreamer-0_10-plugins-base-devel >= 0.10.21-2.21.2
  • gstreamer-0_10-plugins-base-doc >= 0.10.21-2.21.2
  • gstreamer-0_10-plugins-base-lang >= 0.10.21-2.21.2
  • libgstinterfaces-0_10-0 >= 0.10.21-2.21.2
  • libgstinterfaces-0_10-0-32bit >= 0.10.21-2.21.2
SAT Patch Nr: 741
SLES 11 DEBUGINFO
  • gstreamer-0_10-plugins-base-debuginfo >= 0.10.21-2.36.1
  • gstreamer-0_10-plugins-base-debugsource >= 0.10.21-2.36.1
sle11-debuginfo. ia64
sle11-debuginfo. x86
sle11-debuginfo. x86-64
sle11-debuginfo. x86-64
sle11-debuginfo. x86
sle11-debuginfo. s390x
sle11-debuginfo. x86-64
sle11-debuginfo. s390x
sle11-debuginfo. ia64
sle11-debuginfo. x86
sle11-debuginfo. ppc
sle11-debuginfo. ia64
sle11-debuginfo. s390x
sle11-debuginfo. x86
sle11-debuginfo. x86-64
sle11-debuginfo. ppc
sle11-debuginfo. ppc
SAT Patch Nr: 742
SLES 11 DEBUGINFO
  • gstreamer-0_10-plugins-base-debuginfo >= 0.10.21-2.36.1
  • gstreamer-0_10-plugins-base-debuginfo-x86 >= 0.10.21-2.36.1
  • gstreamer-0_10-plugins-base-debugsource >= 0.10.21-2.36.1
sle11-debuginfo. ia64
sle11-debuginfo. x86
sle11-debuginfo. x86-64
sle11-debuginfo. x86-64
sle11-debuginfo. x86
sle11-debuginfo. s390x
sle11-debuginfo. x86-64
sle11-debuginfo. s390x
sle11-debuginfo. ia64
sle11-debuginfo. x86
sle11-debuginfo. ppc
sle11-debuginfo. ia64
sle11-debuginfo. s390x
sle11-debuginfo. x86
sle11-debuginfo. x86-64
sle11-debuginfo. ppc
sle11-debuginfo. ppc
SAT Patch Nr: 742
SLES 11 DEBUGINFO
  • gstreamer-0_10-plugins-base-debuginfo >= 0.10.21-2.36.1
  • gstreamer-0_10-plugins-base-debuginfo-32bit >= 0.10.21-2.36.1
  • gstreamer-0_10-plugins-base-debugsource >= 0.10.21-2.36.1
sle11-debuginfo. ia64
sle11-debuginfo. x86
sle11-debuginfo. x86-64
sle11-debuginfo. x86-64
sle11-debuginfo. x86
sle11-debuginfo. s390x
sle11-debuginfo. x86-64
sle11-debuginfo. s390x
sle11-debuginfo. ia64
sle11-debuginfo. x86
sle11-debuginfo. ppc
sle11-debuginfo. ia64
sle11-debuginfo. s390x
sle11-debuginfo. x86
sle11-debuginfo. x86-64
sle11-debuginfo. ppc
sle11-debuginfo. ppc
SAT Patch Nr: 742
SLE 11
  • gstreamer-0_10-plugins-base-devel >= 0.10.21-2.36.1
sle11-debuginfo. ia64
sle11-debuginfo. x86
sle11-debuginfo. x86-64
sle11-debuginfo. x86-64
sle11-debuginfo. x86
sle11-debuginfo. s390x
sle11-debuginfo. x86-64
sle11-debuginfo. s390x
sle11-debuginfo. ia64
sle11-debuginfo. x86
sle11-debuginfo. ppc
sle11-debuginfo. ia64
sle11-debuginfo. s390x
sle11-debuginfo. x86
sle11-debuginfo. x86-64
sle11-debuginfo. ppc
sle11-debuginfo. ppc
SAT Patch Nr: 742
SLED 11
  • gstreamer-0_10-plugins-base >= 0.10.21-2.36.1
  • gstreamer-0_10-plugins-base-lang >= 0.10.21-2.36.1
  • libgstinterfaces-0_10-0 >= 0.10.21-2.36.1
sle11-debuginfo. ia64
sle11-debuginfo. x86
sle11-debuginfo. x86-64
sle11-debuginfo. x86-64
sle11-debuginfo. x86
sle11-debuginfo. s390x
sle11-debuginfo. x86-64
sle11-debuginfo. s390x
sle11-debuginfo. ia64
sle11-debuginfo. x86
sle11-debuginfo. ppc
sle11-debuginfo. ia64
sle11-debuginfo. s390x
sle11-debuginfo. x86
sle11-debuginfo. x86-64
sle11-debuginfo. ppc
sle11-debuginfo. ppc
SAT Patch Nr: 742
SLED 11
  • gstreamer-0_10-plugins-base >= 0.10.21-2.36.1
  • gstreamer-0_10-plugins-base-32bit >= 0.10.21-2.36.1
  • gstreamer-0_10-plugins-base-lang >= 0.10.21-2.36.1
  • libgstinterfaces-0_10-0 >= 0.10.21-2.36.1
  • libgstinterfaces-0_10-0-32bit >= 0.10.21-2.36.1
sle11-debuginfo. ia64
sle11-debuginfo. x86
sle11-debuginfo. x86-64
sle11-debuginfo. x86-64
sle11-debuginfo. x86
sle11-debuginfo. s390x
sle11-debuginfo. x86-64
sle11-debuginfo. s390x
sle11-debuginfo. ia64
sle11-debuginfo. x86
sle11-debuginfo. ppc
sle11-debuginfo. ia64
sle11-debuginfo. s390x
sle11-debuginfo. x86
sle11-debuginfo. x86-64
sle11-debuginfo. ppc
sle11-debuginfo. ppc
SAT Patch Nr: 742
SLES 11
  • gstreamer-0_10-plugins-base >= 0.10.21-2.36.1
  • gstreamer-0_10-plugins-base-doc >= 0.10.21-2.36.1
  • gstreamer-0_10-plugins-base-lang >= 0.10.21-2.36.1
  • libgstinterfaces-0_10-0 >= 0.10.21-2.36.1
sle11-debuginfo. ia64
sle11-debuginfo. x86
sle11-debuginfo. x86-64
sle11-debuginfo. x86-64
sle11-debuginfo. x86
sle11-debuginfo. s390x
sle11-debuginfo. x86-64
sle11-debuginfo. s390x
sle11-debuginfo. ia64
sle11-debuginfo. x86
sle11-debuginfo. ppc
sle11-debuginfo. ia64
sle11-debuginfo. s390x
sle11-debuginfo. x86
sle11-debuginfo. x86-64
sle11-debuginfo. ppc
sle11-debuginfo. ppc
SAT Patch Nr: 742
SLES 11
  • gstreamer-0_10-plugins-base >= 0.10.21-2.36.1
  • gstreamer-0_10-plugins-base-doc >= 0.10.21-2.36.1
  • gstreamer-0_10-plugins-base-lang >= 0.10.21-2.36.1
  • gstreamer-0_10-plugins-base-x86 >= 0.10.21-2.36.1
  • libgstinterfaces-0_10-0 >= 0.10.21-2.36.1
  • libgstinterfaces-0_10-0-x86 >= 0.10.21-2.36.1
sle11-debuginfo. ia64
sle11-debuginfo. x86
sle11-debuginfo. x86-64
sle11-debuginfo. x86-64
sle11-debuginfo. x86
sle11-debuginfo. s390x
sle11-debuginfo. x86-64
sle11-debuginfo. s390x
sle11-debuginfo. ia64
sle11-debuginfo. x86
sle11-debuginfo. ppc
sle11-debuginfo. ia64
sle11-debuginfo. s390x
sle11-debuginfo. x86
sle11-debuginfo. x86-64
sle11-debuginfo. ppc
sle11-debuginfo. ppc
SAT Patch Nr: 742
SLES 11
  • gstreamer-0_10-plugins-base >= 0.10.21-2.36.1
  • gstreamer-0_10-plugins-base-32bit >= 0.10.21-2.36.1
  • gstreamer-0_10-plugins-base-doc >= 0.10.21-2.36.1
  • gstreamer-0_10-plugins-base-lang >= 0.10.21-2.36.1
  • libgstinterfaces-0_10-0 >= 0.10.21-2.36.1
  • libgstinterfaces-0_10-0-32bit >= 0.10.21-2.36.1
sle11-debuginfo. ia64
sle11-debuginfo. x86
sle11-debuginfo. x86-64
sle11-debuginfo. x86-64
sle11-debuginfo. x86
sle11-debuginfo. s390x
sle11-debuginfo. x86-64
sle11-debuginfo. s390x
sle11-debuginfo. ia64
sle11-debuginfo. x86
sle11-debuginfo. ppc
sle11-debuginfo. ia64
sle11-debuginfo. s390x
sle11-debuginfo. x86
sle11-debuginfo. x86-64
sle11-debuginfo. ppc
sle11-debuginfo. ppc
SAT Patch Nr: 742

Novell® Making IT Work As One

© 2009 Novell, Inc. All Rights Reserved.