Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-9446

Опубликовано: 23 янв. 2017
Источник: debian
EPSS Низкий

Описание

The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated by thumbnailing a simple 1 frame vmnc movie that does not draw to the allocated render canvas.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gst-plugins-bad0.10removedpackage
gst-plugins-bad1.0fixed1.10.1-1package

Примечания

  • http://scarybeastsecurity.blogspot.de/2016/11/0day-poc-risky-design-decisions-in.html

  • Upstream Bug: https://bugzilla.gnome.org/show_bug.cgi?id=774533

  • Fixed by: https://cgit.freedesktop.org/gstreamer/gst-plugins-bad/commit/?id=4cb1bcf1422bbcd79c0f683edb7ee85e3f7a31fe

EPSS

Процентиль: 79%
0.01283
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 9 лет назад

The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated by thumbnailing a simple 1 frame vmnc movie that does not draw to the allocated render canvas.

CVSS3: 4.3
redhat
около 9 лет назад

The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated by thumbnailing a simple 1 frame vmnc movie that does not draw to the allocated render canvas.

CVSS3: 7.5
nvd
около 9 лет назад

The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated by thumbnailing a simple 1 frame vmnc movie that does not draw to the allocated render canvas.

CVSS3: 7.5
github
больше 3 лет назад

The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated by thumbnailing a simple 1 frame vmnc movie that does not draw to the allocated render canvas.

suse-cvrf
около 9 лет назад

Security update for gstreamer-plugins-bad

EPSS

Процентиль: 79%
0.01283
Низкий