The windows_icon_typefind function in gst-plugins-base in GStreamer before 1.10.2, when G_SLICE is set to always-malloc, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted ico file.
The product reads data past the end, or before the beginning, of the intended buffer.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gstreamer | Gstreamer | * | 1.10.1 (including) |
Red Hat Enterprise Linux 7 | RedHat | clutter-gst2-0:2.0.18-1.el7 | * |
Red Hat Enterprise Linux 7 | RedHat | gnome-video-effects-0:0.4.3-1.el7 | * |
Red Hat Enterprise Linux 7 | RedHat | gstreamer1-0:1.10.4-2.el7 | * |
Red Hat Enterprise Linux 7 | RedHat | gstreamer1-plugins-bad-free-0:1.10.4-2.el7 | * |
Red Hat Enterprise Linux 7 | RedHat | gstreamer1-plugins-base-0:1.10.4-1.el7 | * |
Red Hat Enterprise Linux 7 | RedHat | gstreamer1-plugins-good-0:1.10.4-2.el7 | * |
Red Hat Enterprise Linux 7 | RedHat | gstreamer-plugins-bad-free-0:0.10.23-23.el7 | * |
Red Hat Enterprise Linux 7 | RedHat | gstreamer-plugins-good-0:0.10.31-13.el7 | * |
Red Hat Enterprise Linux 7 | RedHat | orc-0:0.4.26-1.el7 | * |
Gst-plugins-base0.10 | Ubuntu | precise | * |
Gst-plugins-base0.10 | Ubuntu | trusty | * |
Gst-plugins-base0.10 | Ubuntu | vivid/stable-phone-overlay | * |
Gst-plugins-base0.10 | Ubuntu | xenial | * |
Gst-plugins-base1.0 | Ubuntu | trusty | * |
Gst-plugins-base1.0 | Ubuntu | upstream | * |
Gst-plugins-base1.0 | Ubuntu | vivid/stable-phone-overlay | * |
Gst-plugins-base1.0 | Ubuntu | xenial | * |
Gst-plugins-base1.0 | Ubuntu | yakkety | * |