Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-9811

Опубликовано: 23 нояб. 2016
Источник: redhat
CVSS3: 4.3
CVSS2: 4.3

Описание

The windows_icon_typefind function in gst-plugins-base in GStreamer before 1.10.2, when G_SLICE is set to always-malloc, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted ico file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5gstreamer-plugins-baseNot affected
Red Hat Enterprise Linux 6gstreamer-plugins-baseNot affected
Red Hat Enterprise Linux 7gstreamer-plugins-baseWill not fix
Red Hat Enterprise Virtualization 3mingw-virt-viewerWill not fix
Red Hat Enterprise Linux 7clutter-gst2FixedRHSA-2017:206001.08.2017
Red Hat Enterprise Linux 7gnome-video-effectsFixedRHSA-2017:206001.08.2017
Red Hat Enterprise Linux 7gstreamer1FixedRHSA-2017:206001.08.2017
Red Hat Enterprise Linux 7gstreamer1-plugins-bad-freeFixedRHSA-2017:206001.08.2017
Red Hat Enterprise Linux 7gstreamer1-plugins-baseFixedRHSA-2017:206001.08.2017
Red Hat Enterprise Linux 7gstreamer1-plugins-goodFixedRHSA-2017:206001.08.2017

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1401918gstreamer: Out of bounds heap read in windows_icon_typefind

4.3 Medium

CVSS3

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 4.7
ubuntu
около 9 лет назад

The windows_icon_typefind function in gst-plugins-base in GStreamer before 1.10.2, when G_SLICE is set to always-malloc, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted ico file.

CVSS3: 4.7
nvd
около 9 лет назад

The windows_icon_typefind function in gst-plugins-base in GStreamer before 1.10.2, when G_SLICE is set to always-malloc, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted ico file.

CVSS3: 4.7
debian
около 9 лет назад

The windows_icon_typefind function in gst-plugins-base in GStreamer be ...

suse-cvrf
около 9 лет назад

Security update for gstreamer-0_10-plugins-base

suse-cvrf
около 9 лет назад

Security update for gstreamer-plugins-base

4.3 Medium

CVSS3

4.3 Medium

CVSS2