PT-2017-10346 · Gstreamer+5 · Gstreamer+6
Hanno Böck
·
Publicado
2016-11-29
·
Atualizado
2021-11-30
·
CVE-2016-9811
CVSS v3.1
4.7
Média
| Vetor | AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
GStreamer versions prior to 1.10.2
gst-plugins-base versions prior to 1.10.2
Description
The issue allows remote attackers to cause a denial of service, specifically an out-of-bounds read, via a crafted ico file. This occurs when the
G SLICE is set to always-malloc. The windows icon typefind function in gst-plugins-base is the vulnerable component.Recommendations
For GStreamer versions prior to 1.10.2, update to version 1.10.2 or later.
For gst-plugins-base versions prior to 1.10.2, update to version 1.10.2 or later.
As a temporary workaround, consider restricting the use of the
windows icon typefind function until a patch is available.Correção
DoS
Out of bounds Read
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Centos
Gstreamer
Red Hat
Suse
Ubuntu
Gst-Plugins-Base