CVE-2016-9635
Summary
| CVE | CVE-2016-9635 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-01-27 22:59:00 UTC |
| Updated | 2018-01-05 02:31:00 UTC |
| Description | Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by providing a 'skip count' that goes beyond initialized buffer. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Bug 774834 – flic decoder: Buffer overflow in flx_decode_delta_fli |
CONFIRM |
bugzilla.gnome.org |
Issue Tracking |
| Red Hat Customer Portal |
REDHAT |
rhn.redhat.com |
Third Party Advisory |
| Debian -- Security Information -- DSA-3724-1 gst-plugins-good0.10 |
DEBIAN |
www.debian.org |
Third Party Advisory |
| GStreamer Good Plug-ins Multiple Buffer Overflow Vulnerabilities |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| Red Hat Customer Portal |
REDHAT |
rhn.redhat.com |
|
| GStreamer 1.10 release notes |
CONFIRM |
gstreamer.freedesktop.org |
Release Notes, Vendor Advisory |
| oss-security - Re: CVE Request: gstreamer plugins |
MLIST |
www.openwall.com |
Mailing List, Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
rhn.redhat.com |
|
| GStreamer plug-ins: User-assisted execution of arbitrary code (GLSA 201705-10) — Gentoo Security |
GENTOO |
security.gentoo.org |
|
| Security: [0day] [exploit] Advancing exploitation: a scriptless 0day exploit against Linux desktops |
MISC |
scarybeastsecurity.blogspot.com |
Exploit, Technical Description |
| Debian -- Security Information -- DSA-3723-1 gst-plugins-good1.0 |
DEBIAN |
www.debian.org |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 378147 Virtuozzo Linux Security Update for gstreamer-plugins-good (VZLSA-2017:0019)
- 378149 Virtuozzo Linux Security Update for gstreamer1-plugins-good (VZLSA-2017:0020)
- 501184 Alpine Linux Security Update for gst-plugins-good
- 504918 Alpine Linux Security Update for gst-plugins-good
- 710553 Gentoo Linux GStreamer plug-ins User-assisted execution of arbitrary code Vulnerability (GLSA 201705-10)