The gst_aac_parse_sink_setcaps function in gst/audioparsers/gstaacparse.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted audio file.
The product reads data past the end, or before the beginning, of the intended buffer.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gstreamer | Gstreamer_project | * | 1.10.2 (including) |
Red Hat Enterprise Linux 7 | RedHat | clutter-gst2-0:2.0.18-1.el7 | * |
Red Hat Enterprise Linux 7 | RedHat | gnome-video-effects-0:0.4.3-1.el7 | * |
Red Hat Enterprise Linux 7 | RedHat | gstreamer1-0:1.10.4-2.el7 | * |
Red Hat Enterprise Linux 7 | RedHat | gstreamer1-plugins-bad-free-0:1.10.4-2.el7 | * |
Red Hat Enterprise Linux 7 | RedHat | gstreamer1-plugins-base-0:1.10.4-1.el7 | * |
Red Hat Enterprise Linux 7 | RedHat | gstreamer1-plugins-good-0:1.10.4-2.el7 | * |
Red Hat Enterprise Linux 7 | RedHat | gstreamer-plugins-bad-free-0:0.10.23-23.el7 | * |
Red Hat Enterprise Linux 7 | RedHat | gstreamer-plugins-good-0:0.10.31-13.el7 | * |
Red Hat Enterprise Linux 7 | RedHat | orc-0:0.4.26-1.el7 | * |
Gst-plugins-good0.10 | Ubuntu | precise | * |
Gst-plugins-good0.10 | Ubuntu | trusty | * |
Gst-plugins-good0.10 | Ubuntu | upstream | * |
Gst-plugins-good0.10 | Ubuntu | vivid/stable-phone-overlay | * |
Gst-plugins-good0.10 | Ubuntu | xenial | * |
Gst-plugins-good1.0 | Ubuntu | trusty | * |
Gst-plugins-good1.0 | Ubuntu | upstream | * |
Gst-plugins-good1.0 | Ubuntu | vivid/stable-phone-overlay | * |
Gst-plugins-good1.0 | Ubuntu | xenial | * |
Gst-plugins-good1.0 | Ubuntu | yakkety | * |