CVE-2016-10199: High severity Gstreamer Project Gstreamer vulnerability
An out-of-bounds read in qtdemuxtagaddstrfull was found that can be triggered by specially crafted file.
Upstream bug:
https://bugzilla.gnome.org/showbug.cgi?id=775451
Upstream patch:
https://github.com/GStreamer/gst-plugins-good/commit/d0949baf3dadea6021d54abef6802fed5a06af75
CVE assignment:
http://seclists.org/oss-sec/2017/q1/284
Other sources
The qtdemuxtagaddstrfull function in gst/isomp4/qtdemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted tag value.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-10199?
CVE-2016-10199 has a high severity due to its potential to cause denial of service through an out-of-bounds read.
How do I fix CVE-2016-10199?
To fix CVE-2016-10199, update GStreamer to version 1.10.3 or later.
What software is affected by CVE-2016-10199?
CVE-2016-10199 affects GStreamer versions prior to 1.10.3 and specifically targets the gstreamer1-plugins-good package.
Can CVE-2016-10199 be exploited remotely?
Yes, CVE-2016-10199 can be exploited remotely through crafted tag values leading to a crash.
Is CVE-2016-10199 a known vulnerability?
Yes, CVE-2016-10199 is a known vulnerability that has been documented and requires prompt attention.