漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Gstreamer1-plugins-ugly-free: gstreamer: out-of-bounds read in realmedia demuxer fileinfo metadata parser
Vulnerability Description
A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a RealMedia file containing a specially crafted FILEINFO metadata section, the demuxer parses variable-name and variable-value pairs using re_skip_pascal_string() without validating that offsets remain within the mapped buffer. Additionally, the element count controlling the parsing loop is read from attacker-controlled data without validation, which can cause an infinite loop. A crafted RealMedia file can cause the application to crash, hang, or potentially read limited adjacent memory contents.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
Vulnerability Type
跨界内存读
Vulnerability Title
gstreamer project RealMedia demuxer 缓冲区错误漏洞
Vulnerability Description
RealMedia demuxer是gstreamer project组织的一个核心组件。 gstreamer project RealMedia demuxer存在缓冲区错误漏洞,该漏洞源于处理RealMedia文件时未验证缓冲区偏移和循环控制元素计数,可能导致应用程序崩溃、挂起或读取邻近内存内容。
CVSS Information
N/A
Vulnerability Type
N/A