First published: Mon Jan 23 2017(Updated: )
The ROM mappings in the NSF decoder in gstreamer 0.10.x allow remote attackers to cause a denial of service (out-of-bounds read or write) and possibly execute arbitrary code via a crafted NSF music file.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
GStreamer | =0.10.0 | |
GStreamer | =0.10.1 | |
GStreamer | =0.10.2 | |
GStreamer | =0.10.3 | |
GStreamer | =0.10.4 | |
GStreamer | =0.10.5 | |
GStreamer | =0.10.6 | |
GStreamer | =0.10.7 | |
GStreamer | =0.10.8 | |
GStreamer | =0.10.9 | |
GStreamer | =0.10.10 | |
GStreamer | =0.10.11 | |
GStreamer | =0.10.12 | |
GStreamer | =0.10.13 | |
GStreamer | =0.10.14 | |
GStreamer | =0.10.15 | |
GStreamer | =0.10.16 | |
GStreamer | =0.10.17 | |
GStreamer | =0.10.18 | |
GStreamer | =0.10.19 | |
GStreamer | =0.10.20 | |
GStreamer | =0.10.21 | |
GStreamer | =0.10.22 | |
GStreamer | =0.10.23 | |
GStreamer | =0.10.24 | |
GStreamer | =0.10.25 | |
GStreamer | =0.10.26 | |
GStreamer | =0.10.27 | |
GStreamer | =0.10.28 | |
GStreamer | =0.10.29 | |
GStreamer | =0.10.30 | |
GStreamer | =0.10.31 | |
GStreamer | =0.10.32 | |
GStreamer | =0.10.33 | |
GStreamer | =0.10.34 | |
GStreamer | =0.10.35 | |
GStreamer | =0.10.36 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9447 has been classified with high severity due to the potential for remote denial of service and arbitrary code execution.
To fix CVE-2016-9447, it is recommended to update GStreamer to the latest version available that addresses this vulnerability.
CVE-2016-9447 affects GStreamer versions 0.10.0 through 0.10.36.
Yes, CVE-2016-9447 can be exploited remotely through crafted NSF music files.
Symptoms of exploitation of CVE-2016-9447 may include unexpected crashes or performance issues in applications using GStreamer.