CVE-2016-10198: Medium severity Gstreamer Project Gstreamer vulnerability
An invalid memory read in gstaacparsesinksetcaps was found that can be triggered by specially crafted file.
Upstream bug:
https://bugzilla.gnome.org/showbug.cgi?id=775450
Upstream patch:
https://github.com/GStreamer/gst-plugins-good/commit/87a2c140ca54c5128093377e9b25a5c24b346727
CVE assignment:
http://seclists.org/oss-sec/2017/q1/284
Other sources
The gstaacparsesinksetcaps function in gst/audioparsers/gstaacparse.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted audio file.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-10198?
CVE-2016-10198 has a severity level that allows remote attackers to cause a denial of service through invalid memory read.
How do I fix CVE-2016-10198?
To fix CVE-2016-10198, upgrade GStreamer to version 1.10.3 or later.
What software is affected by CVE-2016-10198?
CVE-2016-10198 affects GStreamer versions before 1.10.3, specifically the gstreamer1-plugins-good package.
Is there a workaround for CVE-2016-10198?
There are no known workarounds for CVE-2016-10198; patching to a newer version is recommended.
What kind of attack does CVE-2016-10198 enable?
CVE-2016-10198 allows attackers to execute a denial of service attack by exploiting crafted audio files.