Описание
The flx_decode_chunks function in gst/flx/gstflxdec.c in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted FLIC file.
An invalid memory read access flaw was found in GStreamer's FLC/FLI/FLX media file format decoding plug-in. A remote attacker could use this flaw to cause an application using GStreamer to crash.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 5 | gstreamer-plugins-good | Will not fix | ||
Red Hat Enterprise Virtualization 3 | mingw-virt-viewer | Will not fix | ||
Red Hat Enterprise Linux 6 | gstreamer-plugins-good | Fixed | RHSA-2016:2975 | 21.12.2016 |
Red Hat Enterprise Linux 7 | gstreamer-plugins-good | Fixed | RHSA-2017:0019 | 05.01.2017 |
Red Hat Enterprise Linux 7 | gstreamer1-plugins-good | Fixed | RHSA-2017:0020 | 05.01.2017 |
Показывать по
Дополнительная информация
Статус:
EPSS
4.3 Medium
CVSS3
4.3 Medium
CVSS2
Связанные уязвимости
The flx_decode_chunks function in gst/flx/gstflxdec.c in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted FLIC file.
The flx_decode_chunks function in gst/flx/gstflxdec.c in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted FLIC file.
The flx_decode_chunks function in gst/flx/gstflxdec.c in GStreamer bef ...
The flx_decode_chunks function in gst/flx/gstflxdec.c in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted FLIC file.
ELSA-2017-0020: gstreamer1-plugins-good security update (MODERATE)
EPSS
4.3 Medium
CVSS3
4.3 Medium
CVSS2