Описание
Multiple use-after-free vulnerabilities in the (1) gst_mini_object_unref, (2) gst_tag_list_unref, and (3) gst_mxf_demux_update_essence_tracks functions in GStreamer before 1.10.3 allow remote attackers to cause a denial of service (crash) via vectors involving stream tags, as demonstrated by 02785736.mxf.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | gstreamer-plugins-bad-free | Will not fix | ||
| Red Hat Enterprise Virtualization 3 | mingw-virt-viewer | Will not fix | ||
| Red Hat Enterprise Linux 7 | clutter-gst2 | Fixed | RHSA-2017:2060 | 01.08.2017 |
| Red Hat Enterprise Linux 7 | gnome-video-effects | Fixed | RHSA-2017:2060 | 01.08.2017 |
| Red Hat Enterprise Linux 7 | gstreamer1 | Fixed | RHSA-2017:2060 | 01.08.2017 |
| Red Hat Enterprise Linux 7 | gstreamer1-plugins-bad-free | Fixed | RHSA-2017:2060 | 01.08.2017 |
| Red Hat Enterprise Linux 7 | gstreamer1-plugins-base | Fixed | RHSA-2017:2060 | 01.08.2017 |
| Red Hat Enterprise Linux 7 | gstreamer1-plugins-good | Fixed | RHSA-2017:2060 | 01.08.2017 |
| Red Hat Enterprise Linux 7 | gstreamer-plugins-bad-free | Fixed | RHSA-2017:2060 | 01.08.2017 |
| Red Hat Enterprise Linux 7 | gstreamer-plugins-good | Fixed | RHSA-2017:2060 | 01.08.2017 |
Показывать по
Дополнительная информация
Статус:
EPSS
2.5 Low
CVSS3
Связанные уязвимости
Multiple use-after-free vulnerabilities in the (1) gst_mini_object_unref, (2) gst_tag_list_unref, and (3) gst_mxf_demux_update_essence_tracks functions in GStreamer before 1.10.3 allow remote attackers to cause a denial of service (crash) via vectors involving stream tags, as demonstrated by 02785736.mxf.
Multiple use-after-free vulnerabilities in the (1) gst_mini_object_unref, (2) gst_tag_list_unref, and (3) gst_mxf_demux_update_essence_tracks functions in GStreamer before 1.10.3 allow remote attackers to cause a denial of service (crash) via vectors involving stream tags, as demonstrated by 02785736.mxf.
Multiple use-after-free vulnerabilities in the (1) gst_mini_object_unr ...
Multiple use-after-free vulnerabilities in the (1) gst_mini_object_unref, (2) gst_tag_list_unref, and (3) gst_mxf_demux_update_essence_tracks functions in GStreamer before 1.10.3 allow remote attackers to cause a denial of service (crash) via vectors involving stream tags, as demonstrated by 02785736.mxf.
EPSS
2.5 Low
CVSS3