Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-9446

Опубликовано: 15 нояб. 2016
Источник: redhat
CVSS3: 4.3
CVSS2: 4.3
EPSS Низкий

Описание

The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated by thumbnailing a simple 1 frame vmnc movie that does not draw to the allocated render canvas.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gstreamer-plugins-bad-freeWill not fix
Red Hat Enterprise Virtualization 3mingw-gstreamer-plugins-bad-freeWill not fix
Red Hat Enterprise Linux 7clutter-gst2FixedRHSA-2017:206001.08.2017
Red Hat Enterprise Linux 7gnome-video-effectsFixedRHSA-2017:206001.08.2017
Red Hat Enterprise Linux 7gstreamer1FixedRHSA-2017:206001.08.2017
Red Hat Enterprise Linux 7gstreamer1-plugins-bad-freeFixedRHSA-2017:206001.08.2017
Red Hat Enterprise Linux 7gstreamer1-plugins-baseFixedRHSA-2017:206001.08.2017
Red Hat Enterprise Linux 7gstreamer1-plugins-goodFixedRHSA-2017:206001.08.2017
Red Hat Enterprise Linux 7gstreamer-plugins-bad-freeFixedRHSA-2017:206001.08.2017
Red Hat Enterprise Linux 7gstreamer-plugins-goodFixedRHSA-2017:206001.08.2017

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-456
https://bugzilla.redhat.com/show_bug.cgi?id=1397063gstreamer-plugins-bad-free: Missing initialization of allocated heap memory leads to information leak

EPSS

Процентиль: 79%
0.01283
Низкий

4.3 Medium

CVSS3

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 9 лет назад

The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated by thumbnailing a simple 1 frame vmnc movie that does not draw to the allocated render canvas.

CVSS3: 7.5
nvd
около 9 лет назад

The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated by thumbnailing a simple 1 frame vmnc movie that does not draw to the allocated render canvas.

CVSS3: 7.5
debian
около 9 лет назад

The vmnc decoder in the gstreamer does not initialize the render canva ...

CVSS3: 7.5
github
больше 3 лет назад

The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated by thumbnailing a simple 1 frame vmnc movie that does not draw to the allocated render canvas.

suse-cvrf
около 9 лет назад

Security update for gstreamer-plugins-bad

EPSS

Процентиль: 79%
0.01283
Низкий

4.3 Medium

CVSS3

4.3 Medium

CVSS2