CVE-2014-8154
Publication date 27 January 2015
Last updated 24 July 2024
Ubuntu priority
Description
The Gst.MapInfo function in Vala 0.26.0 and 0.26.1 uses an incorrect buffer length declaration for the Gstreamer bindings, which allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via unspecified vectors, which trigger a heap-based buffer overflow.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| vala | ||
| 14.04 LTS trusty | Not in release | |
| vala-0.14 | ||
| 14.04 LTS trusty | Not in release | |
| vala-0.16 | ||
| 14.04 LTS trusty | Not in release | |
| vala-0.18 | ||
| 14.04 LTS trusty | Not in release | |
| vala-0.20 | ||
| 14.04 LTS trusty | Not in release | |
| vala-0.22 | ||
| 14.04 LTS trusty | Not in release | |
| vala-0.26 | ||
| 14.04 LTS trusty | Not in release | |
Notes
mdeslaur
introduced by: https://git.gnome.org/browse/vala/commit/vapi/gstreamer-1.0.vapi?id=c4bf7f02c51d84a91768652a490d2389e2e00092