CVE-2019-9928
published 2019-04-24CVE-2019-9928: GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection parser via a crafted response from a server, potentially allowing remote code…
PriorityP353high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
5.96%
92.5th percentile
GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection parser via a crafted response from a server, potentially allowing remote code execution.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | gst-plugins-base1.0 | < gst-plugins-base1.0 1.14.4-2 (bookworm) | gst-plugins-base1.0 1.14.4-2 (bookworm) |
| gstreamer | gstreamer | < 1.16.0 | 1.16.0 |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability is triggered via a crafted RTSP server response parsed by GStreamer's RTSP connection parser, resulting in a heap-based buffer overflow. Monitor for anomalous or malformed RTSP responses on RTSP traffic (typically TCP port 554) directed at GStreamer-based clients. ↗
- →The attack vector is network-based: a user must open a crafted RTSP stream with a GStreamer application. Detection should focus on GStreamer processes receiving unexpected or malformed RTSP responses from untrusted servers. ↗
- ·Affected versions are GStreamer (gstreamer-plugins-base / gstreamer1-plugins-base) before 1.16.0. Debian fixed the issue in package version 1.14.4-2. Ensure deployed GStreamer versions are at or above these fixed versions. ↗
- ·Red Hat rated this Moderate and marked RHEL 7 packages as 'Will not fix' and RHEL 8 as 'Fix deferred', meaning patched RPMs may not be available for those platforms; compensating controls (e.g., blocking untrusted RTSP sources) should be considered. ↗
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4c4c-7hrr-jfv2: GStreamer before 1
ghsa_unreviewed·2022-05-24
CVE-2019-9928 [HIGH] CWE-787 GHSA-4c4c-7hrr-jfv2: GStreamer before 1
GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection parser via a crafted response from a server, potentially allowing remote code execution.
OSV
CVE-2019-9928: GStreamer before 1
osv·2019-04-24·CVSS 8.8
CVE-2019-9928 [HIGH] CVE-2019-9928: GStreamer before 1
GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection parser via a crafted response from a server, potentially allowing remote code execution.
Ubuntu
GStreamer Base Plugins vulnerability
vendor_ubuntu·2019-04-29
CVE-2019-9928 GStreamer Base Plugins vulnerability
Title: GStreamer Base Plugins vulnerability
Summary: GStreamer Base Plugins could be made to crash or run programs if it
received specially crafted network traffic.
It was discovered that GStreamer Base Plugins did not correctly handle
certain malformed RTSP streams. If a user were tricked into opening a
crafted RTSP stream with a GStreamer application, an attacker could cause a
denial of service via application crash, or possibly execute arbitrary
code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
GStreamer: heap-based buffer overflow in the RTSP connection parser via crafted server response leading to remote code execution
vendor_redhat·2019-04-22·CVSS 8.8
CVE-2019-9928 [HIGH] CWE-122 GStreamer: heap-based buffer overflow in the RTSP connection parser via crafted server response leading to remote code execution
GStreamer: heap-based buffer overflow in the RTSP connection parser via crafted server response leading to remote code execution
GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection parser via a crafted response from a server, potentially allowing remote code execution.
Statement: This issue affects the version of gstreamer-plugins-base and gstreamer1-plugins-base as shipped with Red Hat Enterprise Linux 6, 7 and 8. The security impact has been rated as Moderate by the Red Hat Product Security team.
Red Hat Enterprise Linux 6 is now in Maintenance Support 2 Phase of the support and maintenance life cycle. This has been rated as having a security impact of Moderate, and is not currently planned to be addressed in future updates. For additional information, refer
Debian
CVE-2019-9928: gst-plugins-base1.0 - GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection ...
vendor_debian·2019·CVSS 8.8
CVE-2019-9928 [HIGH] CVE-2019-9928: gst-plugins-base1.0 - GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection ...
GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection parser via a crafted response from a server, potentially allowing remote code execution.
Scope: local
bookworm: resolved (fixed in 1.14.4-2)
bullseye: resolved (fixed in 1.14.4-2)
forky: resolved (fixed in 1.14.4-2)
sid: resolved (fixed in 1.14.4-2)
trixie: resolved (fixed in 1.14.4-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-9928 gstreamer1: GStreamer: heap-based buffer overflow in the RTSP connection parser via crafted server response leading to remote code execution [fedora-all]
bugzilla·2019-06-28·CVSS 8.8
CVE-2019-9928 [HIGH] CVE-2019-9928 gstreamer1: GStreamer: heap-based buffer overflow in the RTSP connection parser via crafted server response leading to remote code execution [fedora-all]
CVE-2019-9928 gstreamer1: GStreamer: heap-based buffer overflow in the RTSP connection parser via crafted server response leading to remote code execution [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM chan
Bugzilla
CVE-2019-9928 mingw-gstreamer1: GStreamer: heap-based buffer overflow in the RTSP connection parser via crafted server response leading to remote code execution [fedora-all]
bugzilla·2019-06-28·CVSS 8.8
CVE-2019-9928 [HIGH] CVE-2019-9928 mingw-gstreamer1: GStreamer: heap-based buffer overflow in the RTSP connection parser via crafted server response leading to remote code execution [fedora-all]
CVE-2019-9928 mingw-gstreamer1: GStreamer: heap-based buffer overflow in the RTSP connection parser via crafted server response leading to remote code execution [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RP
Bugzilla
CVE-2019-9928 mingw-gstreamer: GStreamer: heap-based buffer overflow in the RTSP connection parser via crafted server response leading to remote code execution [fedora-all]
bugzilla·2019-06-28·CVSS 8.8
CVE-2019-9928 [HIGH] CVE-2019-9928 mingw-gstreamer: GStreamer: heap-based buffer overflow in the RTSP connection parser via crafted server response leading to remote code execution [fedora-all]
CVE-2019-9928 mingw-gstreamer: GStreamer: heap-based buffer overflow in the RTSP connection parser via crafted server response leading to remote code execution [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM
Bugzilla
CVE-2019-9928 mingw-gstreamer1-plugins-base: GStreamer: heap-based buffer overflow in the RTSP connection parser via crafted server response leading to remote code execution [epel-7]
bugzilla·2019-06-28·CVSS 8.8
CVE-2019-9928 [HIGH] CVE-2019-9928 mingw-gstreamer1-plugins-base: GStreamer: heap-based buffer overflow in the RTSP connection parser via crafted server response leading to remote code execution [epel-7]
CVE-2019-9928 mingw-gstreamer1-plugins-base: GStreamer: heap-based buffer overflow in the RTSP connection parser via crafted server response leading to remote code execution [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in t
Bugzilla
CVE-2019-9928 mingw-gstreamer1-plugins-base: GStreamer: heap-based buffer overflow in the RTSP connection parser via crafted server response leading to remote code execution [fedora-all]
bugzilla·2019-06-28·CVSS 8.8
CVE-2019-9928 [HIGH] CVE-2019-9928 mingw-gstreamer1-plugins-base: GStreamer: heap-based buffer overflow in the RTSP connection parser via crafted server response leading to remote code execution [fedora-all]
CVE-2019-9928 mingw-gstreamer1-plugins-base: GStreamer: heap-based buffer overflow in the RTSP connection parser via crafted server response leading to remote code execution [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fi
Bugzilla
CVE-2019-9928 mingw-gstreamer1: GStreamer: heap-based buffer overflow in the RTSP connection parser via crafted server response leading to remote code execution [epel-7]
bugzilla·2019-06-28·CVSS 8.8
CVE-2019-9928 [HIGH] CVE-2019-9928 mingw-gstreamer1: GStreamer: heap-based buffer overflow in the RTSP connection parser via crafted server response leading to remote code execution [epel-7]
CVE-2019-9928 mingw-gstreamer1: GStreamer: heap-based buffer overflow in the RTSP connection parser via crafted server response leading to remote code execution [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM change
Bugzilla
CVE-2019-9928 gstreamer-plugins-base: GStreamer: heap-based buffer overflow in the RTSP connection parser via crafted server response leading to remote code execution [fedora-all]
bugzilla·2019-06-28·CVSS 8.8
CVE-2019-9928 [HIGH] CVE-2019-9928 gstreamer-plugins-base: GStreamer: heap-based buffer overflow in the RTSP connection parser via crafted server response leading to remote code execution [fedora-all]
CVE-2019-9928 gstreamer-plugins-base: GStreamer: heap-based buffer overflow in the RTSP connection parser via crafted server response leading to remote code execution [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in
Bugzilla
CVE-2019-9928 gstreamer1-plugins-base: GStreamer: heap-based buffer overflow in the RTSP connection parser via crafted server response leading to remote code execution [fedora-all]
bugzilla·2019-06-28·CVSS 8.8
CVE-2019-9928 [HIGH] CVE-2019-9928 gstreamer1-plugins-base: GStreamer: heap-based buffer overflow in the RTSP connection parser via crafted server response leading to remote code execution [fedora-all]
CVE-2019-9928 gstreamer1-plugins-base: GStreamer: heap-based buffer overflow in the RTSP connection parser via crafted server response leading to remote code execution [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in
Bugzilla
CVE-2019-9928 gstreamer: heap-based buffer overflow in the RTSP connection parser via crafted server response leading to remote code execution [fedora-all]
bugzilla·2019-06-28·CVSS 8.8
CVE-2019-9928 [HIGH] CVE-2019-9928 gstreamer: heap-based buffer overflow in the RTSP connection parser via crafted server response leading to remote code execution [fedora-all]
CVE-2019-9928 gstreamer: heap-based buffer overflow in the RTSP connection parser via crafted server response leading to remote code execution [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and th
Bugzilla
CVE-2019-9928 mingw-gstreamer-plugins-base: GStreamer: heap-based buffer overflow in the RTSP connection parser via crafted server response leading to remote code execution [fedora-all]
bugzilla·2019-06-28·CVSS 8.8
CVE-2019-9928 [HIGH] CVE-2019-9928 mingw-gstreamer-plugins-base: GStreamer: heap-based buffer overflow in the RTSP connection parser via crafted server response leading to remote code execution [fedora-all]
CVE-2019-9928 mingw-gstreamer-plugins-base: GStreamer: heap-based buffer overflow in the RTSP connection parser via crafted server response leading to remote code execution [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fix
Bugzilla
CVE-2019-9928 GStreamer: heap-based buffer overflow in the RTSP connection parser via crafted server response leading to remote code execution
bugzilla·2019-06-28·CVSS 8.8
CVE-2019-9928 [HIGH] CVE-2019-9928 GStreamer: heap-based buffer overflow in the RTSP connection parser via crafted server response leading to remote code execution
CVE-2019-9928 GStreamer: heap-based buffer overflow in the RTSP connection parser via crafted server response leading to remote code execution
GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection parser via a crafted response from a server, potentially allowing remote code execution.
References:
https://gstreamer.freedesktop.org/security/sa-2019-0001.html
Upstream MR:
https://gitlab.freedesktop.org/gstreamer/gst-plugins-base/merge_requests/157
Discussion:
External References:
https://gstreamer.freedesktop.org/security/sa-2019-0001.html
---
Created gstreamer-plugins-base tracking bugs for this issue:
Affects: fedora-all [bug 1725261]
Created mingw-gstreamer1-plugins-base tracking bugs for this issue:
Affects: fedora-all [bug 1725262]
---
Upstream c
Bugzilla
CVE-2019-9928 mingw-gstreamer1-plugins-base: GStreamer: heap-based buffer overflow in the RTSP connection parser via crafted server response leading to remote code execution [fedora-all]
bugzilla·2019-06-28·CVSS 8.8
CVE-2019-9928 [HIGH] CVE-2019-9928 mingw-gstreamer1-plugins-base: GStreamer: heap-based buffer overflow in the RTSP connection parser via crafted server response leading to remote code execution [fedora-all]
CVE-2019-9928 mingw-gstreamer1-plugins-base: GStreamer: heap-based buffer overflow in the RTSP connection parser via crafted server response leading to remote code execution [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fi
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00078.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-06/msg00082.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-05/msg00049.htmlhttps://gstreamer.freedesktop.org/security/https://gstreamer.freedesktop.org/security/sa-2019-0001.htmlhttps://lists.debian.org/debian-lts-announce/2019/04/msg00030.htmlhttps://lists.debian.org/debian-lts-announce/2019/04/msg00031.htmlhttps://seclists.org/bugtraq/2019/Apr/39https://security.gentoo.org/glsa/202003-33https://usn.ubuntu.com/3958-1/https://www.debian.org/security/2019/dsa-4437http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00078.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-06/msg00082.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-05/msg00049.htmlhttps://gstreamer.freedesktop.org/security/https://gstreamer.freedesktop.org/security/sa-2019-0001.htmlhttps://lists.debian.org/debian-lts-announce/2019/04/msg00030.htmlhttps://lists.debian.org/debian-lts-announce/2019/04/msg00031.htmlhttps://seclists.org/bugtraq/2019/Apr/39https://security.gentoo.org/glsa/202003-33https://usn.ubuntu.com/3958-1/https://www.debian.org/security/2019/dsa-4437
2019-04-24
Published