The gst_ps_demux_parse_psm function in gst/mpegdemux/gstmpegdemux.c in gst-plugins-bad in GStreamer allows remote attackers to cause a denial of service (invalid memory read and crash) via vectors involving PSM parsing.
The product reads data past the end, or before the beginning, of the intended buffer.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gstreamer | Gstreamer_project | * | 1.11.2 (excluding) |
Red Hat Enterprise Linux 7 | RedHat | clutter-gst2-0:2.0.18-1.el7 | * |
Red Hat Enterprise Linux 7 | RedHat | gnome-video-effects-0:0.4.3-1.el7 | * |
Red Hat Enterprise Linux 7 | RedHat | gstreamer1-0:1.10.4-2.el7 | * |
Red Hat Enterprise Linux 7 | RedHat | gstreamer1-plugins-bad-free-0:1.10.4-2.el7 | * |
Red Hat Enterprise Linux 7 | RedHat | gstreamer1-plugins-base-0:1.10.4-1.el7 | * |
Red Hat Enterprise Linux 7 | RedHat | gstreamer1-plugins-good-0:1.10.4-2.el7 | * |
Red Hat Enterprise Linux 7 | RedHat | gstreamer-plugins-bad-free-0:0.10.23-23.el7 | * |
Red Hat Enterprise Linux 7 | RedHat | gstreamer-plugins-good-0:0.10.31-13.el7 | * |
Red Hat Enterprise Linux 7 | RedHat | orc-0:0.4.26-1.el7 | * |
Gst-plugins-bad0.10 | Ubuntu | precise | * |
Gst-plugins-bad0.10 | Ubuntu | trusty | * |
Gst-plugins-bad0.10 | Ubuntu | trusty/esm | * |
Gst-plugins-bad0.10 | Ubuntu | upstream | * |
Gst-plugins-bad1.0 | Ubuntu | artful | * |
Gst-plugins-bad1.0 | Ubuntu | esm-apps/xenial | * |
Gst-plugins-bad1.0 | Ubuntu | esm-infra-legacy/trusty | * |
Gst-plugins-bad1.0 | Ubuntu | trusty | * |
Gst-plugins-bad1.0 | Ubuntu | trusty/esm | * |
Gst-plugins-bad1.0 | Ubuntu | upstream | * |
Gst-plugins-bad1.0 | Ubuntu | vivid/stable-phone-overlay | * |
Gst-plugins-bad1.0 | Ubuntu | xenial | * |
Gst-plugins-bad1.0 | Ubuntu | yakkety | * |
Gst-plugins-bad1.0 | Ubuntu | zesty | * |