Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-9809

Опубликовано: 23 нояб. 2016
Источник: redhat
CVSS3: 3.1
CVSS2: 2.6
EPSS Низкий

Описание

Off-by-one error in the gst_h264_parse_set_caps function in GStreamer before 1.10.2 allows remote attackers to have unspecified impact via a crafted file, which triggers an out-of-bounds read.

An out-of-bounds heap read flaw was found in GStreamer's H.264 parser. A remote attacker could use this flaw to cause an application using GStreamer to crash.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gstreamer-plugins-bad-freeNot affected
Red Hat Enterprise Virtualization 3mingw-virt-viewerWill not fix
Red Hat Enterprise Linux 7gstreamer-plugins-bad-freeFixedRHSA-2017:001805.01.2017
Red Hat Enterprise Linux 7gstreamer1-plugins-bad-freeFixedRHSA-2017:002105.01.2017

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-193
https://bugzilla.redhat.com/show_bug.cgi?id=1401880gstreamer-plugins-bad-free: Off-by-one read in gst_h264_parse_set_caps

EPSS

Процентиль: 64%
0.00471
Низкий

3.1 Low

CVSS3

2.6 Low

CVSS2

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 8 лет назад

Off-by-one error in the gst_h264_parse_set_caps function in GStreamer before 1.10.2 allows remote attackers to have unspecified impact via a crafted file, which triggers an out-of-bounds read.

CVSS3: 7.8
nvd
больше 8 лет назад

Off-by-one error in the gst_h264_parse_set_caps function in GStreamer before 1.10.2 allows remote attackers to have unspecified impact via a crafted file, which triggers an out-of-bounds read.

CVSS3: 7.8
debian
больше 8 лет назад

Off-by-one error in the gst_h264_parse_set_caps function in GStreamer ...

suse-cvrf
больше 8 лет назад

Security update for gstreamer-0_10-plugins-bad

suse-cvrf
больше 8 лет назад

Security update for gstreamer-0_10-plugins-bad

EPSS

Процентиль: 64%
0.00471
Низкий

3.1 Low

CVSS3

2.6 Low

CVSS2