DOS / potential heap overwrite in qtdemux using zlib decompression. Integer overflow in qtdemux element in qtdemux_inflate function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities, it could be just a segfault or a heap overwrite.
{ "availability": "No subscription required", "binaries": [ { "binary_version": "1.14.5-0ubuntu1~18.04.3", "binary_name": "gstreamer1.0-gtk3" }, { "binary_version": "1.14.5-0ubuntu1~18.04.3", "binary_name": "gstreamer1.0-plugins-good" }, { "binary_version": "1.14.5-0ubuntu1~18.04.3", "binary_name": "gstreamer1.0-pulseaudio" }, { "binary_version": "1.14.5-0ubuntu1~18.04.3", "binary_name": "gstreamer1.0-qt5" }, { "binary_version": "1.14.5-0ubuntu1~18.04.3", "binary_name": "libgstreamer-plugins-good1.0-0" }, { "binary_version": "1.14.5-0ubuntu1~18.04.3", "binary_name": "libgstreamer-plugins-good1.0-dev" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_version": "1.16.3-0ubuntu1.1", "binary_name": "gstreamer1.0-gtk3" }, { "binary_version": "1.16.3-0ubuntu1.1", "binary_name": "gstreamer1.0-plugins-good" }, { "binary_version": "1.16.3-0ubuntu1.1", "binary_name": "gstreamer1.0-pulseaudio" }, { "binary_version": "1.16.3-0ubuntu1.1", "binary_name": "gstreamer1.0-qt5" }, { "binary_version": "1.16.3-0ubuntu1.1", "binary_name": "libgstreamer-plugins-good1.0-0" }, { "binary_version": "1.16.3-0ubuntu1.1", "binary_name": "libgstreamer-plugins-good1.0-dev" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_version": "1.20.3-0ubuntu1", "binary_name": "gstreamer1.0-gtk3" }, { "binary_version": "1.20.3-0ubuntu1", "binary_name": "gstreamer1.0-plugins-good" }, { "binary_version": "1.20.3-0ubuntu1", "binary_name": "gstreamer1.0-pulseaudio" }, { "binary_version": "1.20.3-0ubuntu1", "binary_name": "gstreamer1.0-qt5" }, { "binary_version": "1.20.3-0ubuntu1", "binary_name": "libgstreamer-plugins-good1.0-0" }, { "binary_version": "1.20.3-0ubuntu1", "binary_name": "libgstreamer-plugins-good1.0-dev" } ] }
{ "binaries": [ { "binary_version": "11.0.11+0-1", "binary_name": "libopenjfx-java" }, { "binary_version": "11.0.11+0-1", "binary_name": "libopenjfx-jni" }, { "binary_version": "11.0.11+0-1", "binary_name": "openjfx" }, { "binary_version": "11.0.11+0-1", "binary_name": "openjfx-source" } ] }
{ "binaries": [ { "binary_version": "11.0.11+1-3.1ubuntu5", "binary_name": "libopenjfx-java" }, { "binary_version": "11.0.11+1-3.1ubuntu5", "binary_name": "libopenjfx-jni" }, { "binary_version": "11.0.11+1-3.1ubuntu5", "binary_name": "openjfx" }, { "binary_version": "11.0.11+1-3.1ubuntu5", "binary_name": "openjfx-source" } ] }
{ "binaries": [ { "binary_version": "11.0.11+1-6", "binary_name": "libopenjfx-java" }, { "binary_version": "11.0.11+1-6", "binary_name": "libopenjfx-jni" }, { "binary_version": "11.0.11+1-6", "binary_name": "openjfx" }, { "binary_version": "11.0.11+1-6", "binary_name": "openjfx-source" } ] }
{ "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro", "binaries": [ { "binary_version": "1.8.3-1ubuntu0.5+esm1", "binary_name": "gstreamer1.0-plugins-good" }, { "binary_version": "1.8.3-1ubuntu0.5+esm1", "binary_name": "gstreamer1.0-pulseaudio" }, { "binary_version": "1.8.3-1ubuntu0.5+esm1", "binary_name": "libgstreamer-plugins-good1.0-0" }, { "binary_version": "1.8.3-1ubuntu0.5+esm1", "binary_name": "libgstreamer-plugins-good1.0-dev" } ] }
{ "binaries": [ { "binary_version": "11.0.2+1-1~18.04.2", "binary_name": "libopenjfx-java" }, { "binary_version": "11.0.2+1-1~18.04.2", "binary_name": "libopenjfx-jni" }, { "binary_version": "11.0.2+1-1~18.04.2", "binary_name": "openjfx" }, { "binary_version": "11.0.2+1-1~18.04.2", "binary_name": "openjfx-source" } ] }
{ "binaries": [ { "binary_version": "11.0.7+0-2ubuntu2", "binary_name": "libopenjfx-java" }, { "binary_version": "11.0.7+0-2ubuntu2", "binary_name": "libopenjfx-jni" }, { "binary_version": "11.0.7+0-2ubuntu2", "binary_name": "openjfx" }, { "binary_version": "11.0.7+0-2ubuntu2", "binary_name": "openjfx-source" } ] }