[arch-security] [ASA-201701-3] gst-plugins-bad: multiple issues
santiago at archlinux.org
Mon Jan 2 21:46:13 UTC 2017
Arch Linux Security Advisory ASA-201701-3
Date : 2017-01-02
CVE-ID : CVE-2016-9445 CVE-2016-9446
Package : gst-plugins-bad
Type : multiple issues
Remote : Yes
Link : https://security.archlinux.org/AVG-76
The package gst-plugins-bad before version 1.10.2-2 is vulnerable to
multiple issues including arbitrary code execution and information
Upgrade to 1.10.2-2.
# pacman -Syu "gst-plugins-bad>=1.10.2-2"
The problems have been fixed upstream in version 1.10.2.
- CVE-2016-9445 (arbitrary code execution)
The vmnc decoder in gst-plugins-bad of the gstreamer code base contains
a width * height * depth integer overflow in the allocation of the
render buffer inside gst/vmnc/vmncdec.c.
- CVE-2016-9446 (information disclosure)
An information disclosure vulnerability has been discovered in the
render canvas functionality of gst-plugins-bad due to the lack of
initializing the returned heap area of g_malloc(). An example for the
information leak would be thumbnailing a simple 1 frame vmnc movie that
does not draw to the allocated render canvas at all.
This could be a problem for anyone using gstreamer in a server
environment to provide a thumbnailing services.
An attacker is able to provide a crafted VMNC file that would allow for
either arbitrary code execution or disclose information of the memory
of the running host.
-------------- next part --------------
A non-text attachment was scrubbed...
Size: 833 bytes
Desc: not available
More information about the arch-security