The ROM mappings in the NSF decoder in gstreamer 0.10.x allow remote attackers to cause a denial of service (out-of-bounds read or write) and possibly execute arbitrary code via a crafted NSF music file.
The product reads data past the end, or before the beginning, of the intended buffer.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gstreamer | Gstreamer_project | 0.10.0 (including) | 0.10.0 (including) |
Gstreamer | Gstreamer_project | 0.10.1 (including) | 0.10.1 (including) |
Gstreamer | Gstreamer_project | 0.10.2 (including) | 0.10.2 (including) |
Gstreamer | Gstreamer_project | 0.10.3 (including) | 0.10.3 (including) |
Gstreamer | Gstreamer_project | 0.10.4 (including) | 0.10.4 (including) |
Gstreamer | Gstreamer_project | 0.10.5 (including) | 0.10.5 (including) |
Gstreamer | Gstreamer_project | 0.10.6 (including) | 0.10.6 (including) |
Gstreamer | Gstreamer_project | 0.10.7 (including) | 0.10.7 (including) |
Gstreamer | Gstreamer_project | 0.10.8 (including) | 0.10.8 (including) |
Gstreamer | Gstreamer_project | 0.10.9 (including) | 0.10.9 (including) |
Gstreamer | Gstreamer_project | 0.10.10 (including) | 0.10.10 (including) |
Gstreamer | Gstreamer_project | 0.10.11 (including) | 0.10.11 (including) |
Gstreamer | Gstreamer_project | 0.10.12 (including) | 0.10.12 (including) |
Gstreamer | Gstreamer_project | 0.10.13 (including) | 0.10.13 (including) |
Gstreamer | Gstreamer_project | 0.10.14 (including) | 0.10.14 (including) |
Gstreamer | Gstreamer_project | 0.10.15 (including) | 0.10.15 (including) |
Gstreamer | Gstreamer_project | 0.10.16 (including) | 0.10.16 (including) |
Gstreamer | Gstreamer_project | 0.10.17 (including) | 0.10.17 (including) |
Gstreamer | Gstreamer_project | 0.10.18 (including) | 0.10.18 (including) |
Gstreamer | Gstreamer_project | 0.10.19 (including) | 0.10.19 (including) |
Gstreamer | Gstreamer_project | 0.10.20 (including) | 0.10.20 (including) |
Gstreamer | Gstreamer_project | 0.10.21 (including) | 0.10.21 (including) |
Gstreamer | Gstreamer_project | 0.10.22 (including) | 0.10.22 (including) |
Gstreamer | Gstreamer_project | 0.10.23 (including) | 0.10.23 (including) |
Gstreamer | Gstreamer_project | 0.10.24 (including) | 0.10.24 (including) |
Gstreamer | Gstreamer_project | 0.10.25 (including) | 0.10.25 (including) |
Gstreamer | Gstreamer_project | 0.10.26 (including) | 0.10.26 (including) |
Gstreamer | Gstreamer_project | 0.10.27 (including) | 0.10.27 (including) |
Gstreamer | Gstreamer_project | 0.10.28 (including) | 0.10.28 (including) |
Gstreamer | Gstreamer_project | 0.10.29 (including) | 0.10.29 (including) |
Gstreamer | Gstreamer_project | 0.10.30 (including) | 0.10.30 (including) |
Gstreamer | Gstreamer_project | 0.10.31 (including) | 0.10.31 (including) |
Gstreamer | Gstreamer_project | 0.10.32 (including) | 0.10.32 (including) |
Gstreamer | Gstreamer_project | 0.10.33 (including) | 0.10.33 (including) |
Gstreamer | Gstreamer_project | 0.10.34 (including) | 0.10.34 (including) |
Gstreamer | Gstreamer_project | 0.10.35 (including) | 0.10.35 (including) |
Gstreamer | Gstreamer_project | 0.10.36 (including) | 0.10.36 (including) |
Red Hat Enterprise Linux 6 | RedHat | gstreamer-plugins-bad-free-0:0.10.19-5.el6_8 | * |
Red Hat Enterprise Linux 7 | RedHat | gstreamer-plugins-bad-free-0:0.10.23-22.el7_3 | * |
Gst-plugins-bad0.10 | Ubuntu | precise | * |
Gst-plugins-bad0.10 | Ubuntu | trusty | * |