PT-2017-10343 · Gstreamer+4 · Gstreamer+4

Chris Evans

+1

·

Publicado

2016-11-29

·

Atualizado

2018-01-05

·

CVE-2016-9808

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GStreamer versions prior to 1.10.2
Description The issue allows remote attackers to cause a denial of service, resulting in an out-of-bounds write and crash, via a crafted series of skip and count pairs in the FLIC decoder.
Recommendations For versions prior to 1.10.2, update to version 1.10.2 or later to resolve the issue. As a temporary workaround, consider disabling the FLIC decoder until a patch is available. Restrict access to the FLIC decoder module to minimize the risk of exploitation.

Exploit

Correção

DoS

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-2372
CESA-2016_2975
CESA-2017_0019
CESA-2017_0020
CVE-2016-9808
MGASA-2016-0424
OPENSUSE-SU-2017_0071-1
OPENSUSE-SU-2017_0141-1
OPENSUSE-SU-2017_0151-1
OPENSUSE-SU-2017_0160-1
OPENSUSE-SU-2017_0298-1
RHSA-2016:2975
RHSA-2016_2975
RHSA-2017:0019
RHSA-2017:0020
RHSA-2017_0019
RHSA-2017_0020
SUSE-SU-2016:3288-1
SUSE-SU-2016:3303-1
SUSE-SU-2017:0210-1
SUSE-SU-2017:0225-1
SUSE-SU-2017:0237-1

Produtos afetados

Alt Linux
Centos
Gstreamer
Red Hat
Suse