Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-9445

Опубликовано: 23 янв. 2017
Источник: debian

Описание

Integer overflow in the vmnc decoder in the gstreamer allows remote attackers to cause a denial of service (crash) via large width and height values, which triggers a buffer overflow.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gst-plugins-bad0.10removedpackage
gst-plugins-bad1.0fixed1.10.1-1package

Примечания

  • http://scarybeastsecurity.blogspot.de/2016/11/0day-poc-risky-design-decisions-in.html

  • Upstream Bug: https://bugzilla.gnome.org/show_bug.cgi?id=774533

  • Fixed by: https://cgit.freedesktop.org/gstreamer/gst-plugins-bad/commit/?id=4cb1bcf1422bbcd79c0f683edb7ee85e3f7a31fe

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

Integer overflow in the vmnc decoder in the gstreamer allows remote attackers to cause a denial of service (crash) via large width and height values, which triggers a buffer overflow.

CVSS3: 7.5
redhat
почти 9 лет назад

Integer overflow in the vmnc decoder in the gstreamer allows remote attackers to cause a denial of service (crash) via large width and height values, which triggers a buffer overflow.

CVSS3: 7.5
nvd
больше 8 лет назад

Integer overflow in the vmnc decoder in the gstreamer allows remote attackers to cause a denial of service (crash) via large width and height values, which triggers a buffer overflow.

CVSS3: 7.5
github
больше 3 лет назад

Integer overflow in the vmnc decoder in the gstreamer allows remote attackers to cause a denial of service (crash) via large width and height values, which triggers a buffer overflow.

suse-cvrf
больше 8 лет назад

Security update for gstreamer-plugins-bad