CVE-2016-9813
GStreamer gst-plugins-bad Plugin - NULL Pointer Dereference
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
The _parse_pat function in the mpegts parser in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted file.
La función _parse_pat en el intérprete mpegts en GStreamer en versiones anteriores a 1.10.2 permite a atacantes remotos provocar una denegación de servicio (referencia a puntero NULL y caída) a través de un archivo manipulado.
A NULL pointer dereference flaw was found in GStreamer's MPEG-TS parser. A remote attacker could use this flaw to cause an application using GStreamer to crash.
GStreamer is a streaming media framework based on graphs of filters which operate on media data. The gstreamer1-plugins-bad-free package contains a collection of plug-ins for GStreamer. Security Fix: An integer overflow flaw, leading to a heap-based buffer overflow, was found in GStreamer's VMware VMnc video file format decoding plug-in. A remote attacker could use this flaw to cause an application using GStreamer to crash or, potentially, execute arbitrary code with the privileges of the user running the application.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-12-04 CVE Reserved
- 2017-01-05 CVE Published
- 2017-06-13 First Exploit
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-476: NULL Pointer Dereference
CAPEC
References (12)
URL | Tag | Source |
---|---|---|
http://www.openwall.com/lists/oss-security/2016/12/01/2 | Mailing List |
|
http://www.openwall.com/lists/oss-security/2016/12/05/8 | Mailing List |
|
http://www.securityfocus.com/bid/95158 | Third Party Advisory | |
https://bugzilla.gnome.org/show_bug.cgi?id=775120 | Issue Tracking |
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/142914 | 2017-06-13 | |
https://www.exploit-db.com/exploits/42162 | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2017-0021.html | 2018-01-05 | |
http://www.debian.org/security/2017/dsa-3818 | 2018-01-05 | |
https://gstreamer.freedesktop.org/releases/1.10/#1.10.2 | 2018-01-05 | |
https://security.gentoo.org/glsa/201705-10 | 2018-01-05 | |
https://access.redhat.com/security/cve/CVE-2016-9813 | 2017-01-05 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1401934 | 2017-01-05 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Gstreamer Search vendor "Gstreamer" | Gstreamer Search vendor "Gstreamer" for product "Gstreamer" | <= 1.10.1 Search vendor "Gstreamer" for product "Gstreamer" and version " <= 1.10.1" | - |
Affected
|