PYSEC-2009-15

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/gstreamer-plugins/PYSEC-2009-15.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2009-15
Aliases
  • CVE-2009-0387
Published
2009-02-02T19:30:00.377Z
Modified
2026-05-21T15:00:14.132892482Z
Summary
[none]
Details

Array index error in the qtdemuxparsesamples function in gst/qtdemux/qtdemux.c in GStreamer Good Plug-ins (aka gst-plugins-good) 0.10.9 through 0.10.11 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted Sync Sample (aka stss) atom data in a malformed QuickTime media .mov file, related to "mark keyframes."

References

Affected packages

PyPI / gstreamer-plugins

Package

Name
gstreamer-plugins
View open source insights on deps.dev
Purl
pkg:pypi/gstreamer-plugins

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
0.10.9
Last affected
0.10.10
Last affected
0.10.11
Last affected
0.8.5

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/gstreamer-plugins/PYSEC-2009-15.yaml"