The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated by thumbnailing a simple 1 frame vmnc movie that does not draw to the allocated render canvas.
The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gstreamer | Gstreamer_project | * | 1.11.1 (excluding) |
Gst-plugins-bad0.10 | Ubuntu | precise | * |
Gst-plugins-bad0.10 | Ubuntu | trusty | * |
Gst-plugins-bad1.0 | Ubuntu | devel | * |
Gst-plugins-bad1.0 | Ubuntu | trusty | * |
Gst-plugins-bad1.0 | Ubuntu | upstream | * |
Gst-plugins-bad1.0 | Ubuntu | vivid/stable-phone-overlay | * |
Gst-plugins-bad1.0 | Ubuntu | xenial | * |
Gst-plugins-bad1.0 | Ubuntu | yakkety | * |
Gst-plugins-bad1.0 | Ubuntu | zesty | * |
Red Hat Enterprise Linux 7 | RedHat | clutter-gst2-0:2.0.18-1.el7 | * |
Red Hat Enterprise Linux 7 | RedHat | gnome-video-effects-0:0.4.3-1.el7 | * |
Red Hat Enterprise Linux 7 | RedHat | gstreamer1-0:1.10.4-2.el7 | * |
Red Hat Enterprise Linux 7 | RedHat | gstreamer1-plugins-bad-free-0:1.10.4-2.el7 | * |
Red Hat Enterprise Linux 7 | RedHat | gstreamer1-plugins-base-0:1.10.4-1.el7 | * |
Red Hat Enterprise Linux 7 | RedHat | gstreamer1-plugins-good-0:1.10.4-2.el7 | * |
Red Hat Enterprise Linux 7 | RedHat | gstreamer-plugins-bad-free-0:0.10.23-23.el7 | * |
Red Hat Enterprise Linux 7 | RedHat | gstreamer-plugins-good-0:0.10.31-13.el7 | * |
Red Hat Enterprise Linux 7 | RedHat | orc-0:0.4.26-1.el7 | * |