CVE-2009-1932

Severity CVSS v4.0:
Pending analysis
Type:
CWE-189 Numeric Errors
Publication date:
04/06/2009
Last modified:
09/04/2025

Description

Multiple integer overflows in the (1) user_info_callback, (2) user_endrow_callback, and (3) gst_pngdec_task functions (ext/libpng/gstpngdec.c) in GStreamer Good Plug-ins (aka gst-plugins-good or gstreamer-plugins-good) 0.10.15 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted PNG file, which triggers a buffer overflow.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gstreamer:good_plug-ins:0.10.15:*:*:*:*:*:*:*