PYSEC-2009-14

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/gstreamer-plugins/PYSEC-2009-14.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2009-14
Aliases
  • CVE-2009-0386
Published
2009-02-02T19:30:00.343Z
Modified
2026-05-21T15:00:13.747134369Z
Summary
[none]
Details

Heap-based buffer overflow in the qtdemuxparsesamples function in gst/qtdemux/qtdemux.c in GStreamer Good Plug-ins (aka gst-plugins-good) 0.10.9 through 0.10.11 might allow remote attackers to execute arbitrary code via crafted Composition Time To Sample (ctts) atom data in a malformed QuickTime media .mov file.

References

Affected packages

PyPI / gstreamer-plugins

Package

Name
gstreamer-plugins
View open source insights on deps.dev
Purl
pkg:pypi/gstreamer-plugins

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
0.10.9
Last affected
0.10.10
Last affected
0.10.11

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/gstreamer-plugins/PYSEC-2009-14.yaml"