First published: Mon Feb 06 2017(Updated: )
The gst_aac_parse_sink_setcaps function in gst/audioparsers/gstaacparse.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted audio file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/gstreamer1-plugins-good | <1.10.3 | 1.10.3 |
GStreamer | <=1.10.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-10198 has a severity level that allows remote attackers to cause a denial of service through invalid memory read.
To fix CVE-2016-10198, upgrade GStreamer to version 1.10.3 or later.
CVE-2016-10198 affects GStreamer versions before 1.10.3, specifically the gstreamer1-plugins-good package.
There are no known workarounds for CVE-2016-10198; patching to a newer version is recommended.
CVE-2016-10198 allows attackers to execute a denial of service attack by exploiting crafted audio files.