Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-9807

Опубликовано: 22 нояб. 2016
Источник: redhat
CVSS3: 4.3
CVSS2: 4.3
EPSS Низкий

Описание

The flx_decode_chunks function in gst/flx/gstflxdec.c in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted FLIC file.

An invalid memory read access flaw was found in GStreamer's FLC/FLI/FLX media file format decoding plug-in. A remote attacker could use this flaw to cause an application using GStreamer to crash.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5gstreamer-plugins-goodWill not fix
Red Hat Enterprise Virtualization 3mingw-virt-viewerWill not fix
Red Hat Enterprise Linux 6gstreamer-plugins-goodFixedRHSA-2016:297521.12.2016
Red Hat Enterprise Linux 7gstreamer-plugins-goodFixedRHSA-2017:001905.01.2017
Red Hat Enterprise Linux 7gstreamer1-plugins-goodFixedRHSA-2017:002005.01.2017

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1401874gstreamer-plugins-good: Invalid memory read in flx_decode_chunks

EPSS

Процентиль: 72%
0.00765
Низкий

4.3 Medium

CVSS3

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 8 лет назад

The flx_decode_chunks function in gst/flx/gstflxdec.c in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted FLIC file.

CVSS3: 5.5
nvd
больше 8 лет назад

The flx_decode_chunks function in gst/flx/gstflxdec.c in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted FLIC file.

CVSS3: 5.5
debian
больше 8 лет назад

The flx_decode_chunks function in gst/flx/gstflxdec.c in GStreamer bef ...

CVSS3: 5.5
github
больше 3 лет назад

The flx_decode_chunks function in gst/flx/gstflxdec.c in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted FLIC file.

oracle-oval
больше 8 лет назад

ELSA-2017-0020: gstreamer1-plugins-good security update (MODERATE)

EPSS

Процентиль: 72%
0.00765
Низкий

4.3 Medium

CVSS3

4.3 Medium

CVSS2