PT-2017-10344 · Gstreamer+4 · Gstreamer+4

Hanno Böck

·

Published

2016-11-29

·

Updated

2020-03-31

·

CVE-2016-9809

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GStreamer versions prior to 1.10.2
Description The issue is caused by an off-by-one error in the gst h264 parse set caps function, allowing remote attackers to have an unspecified impact via a crafted file. This triggers an out-of-bounds read.
Recommendations For versions prior to 1.10.2, update to version 1.10.2 or later to resolve the issue.

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-2372
CESA-2017_0018
CESA-2017_0021
CVE-2016-9809
DLA-2164-1
DLA-736-1
DSA-3818-1
MGASA-2018-0012
MGASA-2018-0013
RHSA-2017:0018
RHSA-2017:0021
RHSA-2017_0018
RHSA-2017_0021
SUSE-SU-2016:3296-1
SUSE-SU-2016:3297-1
SUSE-SU-2017:0330-1
SUSE-SU-2017:0331-1
SUSE-SU-2017_0330-1
SUSE-SU-2017_0331-1

Affected Products

Alt Linux
Centos
Gstreamer
Red Hat
Suse