PT-2017-10140 · Gstreamer+4 · Gstreamer+4

Chris Evans

·

Publicado

2016-11-17

·

Atualizado

2020-02-24

·

CVE-2016-9445

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions gstreamer (affected versions not specified)
Description The issue is related to an integer overflow in the vmnc decoder, which can be exploited by remote attackers to cause a denial of service (crash) by providing large width and height values, triggering a buffer overflow.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Integer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-2308
CESA-2016_2974
CESA-2017_0018
CESA-2017_0021
CVE-2016-9445
DLA-712-1
DSA-3717-1
MGASA-2018-0012
OPENSUSE-SU-2016_3147-1
OPENSUSE-SU-2016_3158-1
RHSA-2016:2974
RHSA-2016_2974
RHSA-2017:0018
RHSA-2017:0021
RHSA-2017_0018
RHSA-2017_0021
SUSE-SU-2016:3296-1
SUSE-SU-2016:3297-1
SUSE-SU-2016_3296-1
SUSE-SU-2016_3297-1
SUSE-SU-2017:0027-1
SUSE-SU-2017:0028-1
SUSE-SU-2017_0027-1
SUSE-SU-2017_0028-1

Produtos afetados

Alt Linux
Centos
Red Hat
Suse
Gstreamer