Back

HIGH

Vala: Heap-buffer overflow in vala-gstreamer bindings at Gst.MapInfo()

Published Jan 27, 2015

Description

The Gst.MapInfo function in Vala 0.26.0 and 0.26.1 uses an incorrect buffer length declaration for the Gstreamer bindings, which allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via unspecified vectors, which trigger a heap-based buffer overflow.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue does not affect the version of vala package as shipped with Red Hat Enterprise Linux 7.

Metrics

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jan 27, 2015
Updated Aug 6, 2024
Reserved Oct 10, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jan 13, 2015