CVE-2016-9445
gstreamer-plugins-bad-free: Integer overflow when allocating render buffer in VMnc decoder
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Integer overflow in the vmnc decoder in the gstreamer allows remote attackers to cause a denial of service (crash) via large width and height values, which triggers a buffer overflow.
Desbordamiento de entero en el decodificador vmnc en el gstreamer permite a atacantes remotos provocar una denegación de servicio (caída) a través de valores de anchura y altura grandes, lo que desencadena un desbordamiento de búfer.
An integer overflow flaw, leading to a heap-based buffer overflow, was found in GStreamer's VMware VMnc video file format decoding plug-in. A remote attacker could use this flaw to cause an application using GStreamer to crash or, potentially, execute arbitrary code with the privileges of the user running the application.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-11-18 CVE Reserved
- 2016-12-21 CVE Published
- 2024-04-25 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-122: Heap-based Buffer Overflow
- CWE-190: Integer Overflow or Wraparound
CAPEC
References (12)
URL | Tag | Source |
---|---|---|
http://www.openwall.com/lists/oss-security/2016/11/18/12 | Mailing List | |
http://www.openwall.com/lists/oss-security/2016/11/18/13 | Mailing List | |
http://www.securityfocus.com/bid/94421 | Vdb Entry | |
https://bugzilla.gnome.org/show_bug.cgi?id=774533 | X_refsource_confirm | |
https://cgit.freedesktop.org/gstreamer/gst-plugins-bad/commit/gst/vmnc/vmncdec.c?id=4cb1bcf1422bbcd79c0f683edb7ee85e3f7a31fe | X_refsource_confirm | |
https://scarybeastsecurity.blogspot.de/2016/11/0day-poc-risky-design-decisions-in.html | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2016-2974.html | 2023-11-07 | |
http://rhn.redhat.com/errata/RHSA-2017-0018.html | 2023-11-07 | |
http://rhn.redhat.com/errata/RHSA-2017-0021.html | 2023-11-07 | |
https://security.gentoo.org/glsa/201705-10 | 2023-11-07 | |
https://access.redhat.com/security/cve/CVE-2016-9445 | 2017-01-05 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1395767 | 2017-01-05 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Gstreamer Project Search vendor "Gstreamer Project" | Gstreamer Search vendor "Gstreamer Project" for product "Gstreamer" | 1.10.0 Search vendor "Gstreamer Project" for product "Gstreamer" and version "1.10.0" | - |
Affected
|