漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Gstreamer1-plugins-bad-free: gstreamer: signed integer overflow in vmnc decoder cursor payload handling
Vulnerability Description
A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream with large cursor dimensions can overflow signed integer payload-size arithmetic, bypassing a length check and leading to out-of-bounds reads. A remote attacker could trick a user into opening a specially crafted VMnc file, potentially causing a crash or information disclosure.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
Vulnerability Type
整数溢出或超界折返
Vulnerability Title
GStreamer VMnc decoder 数字错误漏洞
Vulnerability Description
VMnc decoder是GStreamer组织的一个视频解码器插件。 GStreamer VMnc decoder存在数字错误漏洞,该漏洞源于符号整数溢出,导致绕过长度检查并越界读取。远程攻击者可能诱使用户打开特制的VMnc文件,从而导致崩溃或信息泄露。
CVSS Information
N/A
Vulnerability Type
N/A