The gst_decode_chain_free_internal function in the flxdex decoder in gst-plugins-good in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (invalid memory read and crash) via an invalid file, which triggers an incorrect unref call.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/95163 | third party advisory vdb entry |
https://gstreamer.freedesktop.org/releases/1.10/#1.10.2 | release notes vendor advisory |
https://access.redhat.com/errata/RHSA-2017:2060 | vendor advisory |
https://bugzilla.gnome.org/show_bug.cgi?id=774897 | issue tracking |
http://www.openwall.com/lists/oss-security/2016/12/05/8 | third party advisory mailing list |
https://security.gentoo.org/glsa/201705-10 | vendor advisory |
http://www.openwall.com/lists/oss-security/2016/12/01/2 | third party advisory mailing list |