CVE-2014-8154

Publication date 27 January 2015

Last updated 24 July 2024


Ubuntu priority

Description

The Gst.MapInfo function in Vala 0.26.0 and 0.26.1 uses an incorrect buffer length declaration for the Gstreamer bindings, which allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via unspecified vectors, which trigger a heap-based buffer overflow.

Read the notes from the security team

Status

Package Ubuntu Release Status
vala 14.10 utopic Not in release
14.04 LTS trusty Not in release
12.04 LTS precise
Not affected
10.04 LTS lucid Ignored end of life
vala-0.14 14.10 utopic
Not affected
14.04 LTS trusty Not in release
12.04 LTS precise
Not affected
10.04 LTS lucid Not in release
vala-0.16 14.10 utopic
Not affected
14.04 LTS trusty Not in release
12.04 LTS precise
Not affected
10.04 LTS lucid Not in release
vala-0.18 14.10 utopic
Not affected
14.04 LTS trusty Not in release
12.04 LTS precise Not in release
10.04 LTS lucid Not in release
vala-0.20 14.10 utopic
Not affected
14.04 LTS trusty Not in release
12.04 LTS precise Not in release
10.04 LTS lucid Not in release
vala-0.22 14.10 utopic Not in release
14.04 LTS trusty Not in release
12.04 LTS precise Not in release
10.04 LTS lucid Not in release
vala-0.26 14.10 utopic Not in release
14.04 LTS trusty Not in release
12.04 LTS precise Not in release
10.04 LTS lucid Not in release

Notes


mdeslaur

introduced by: https://git.gnome.org/browse/vala/commit/vapi/gstreamer-1.0.vapi?id=c4bf7f02c51d84a91768652a490d2389e2e00092

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
vala-0.26

Access our resources on patching vulnerabilities