First published: Tue Dec 06 2016(Updated: )
The gst_decode_chain_free_internal function in the flxdex decoder in gst-plugins-good in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (invalid memory read and crash) via an invalid file, which triggers an incorrect unref call.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/gstreamer1-plugins-good | <1.8 | 1.8 |
GStreamer | <=1.10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9810 has a severity rating that indicates it poses a denial of service risk due to potential crashes from invalid memory reads.
To fix CVE-2016-9810, it is recommended to upgrade GStreamer to version 1.10.2 or later.
CVE-2016-9810 affects GStreamer versions prior to 1.10.2 and specifically versions up to 1.8.
CVE-2016-9810 can be exploited by remote attackers through the use of invalid files that trigger a denial of service.
Yes, CVE-2016-9810 is related to the flxdex decoder in the gst-plugins-good component of GStreamer.