CVE-2016-9810: Medium severity GStreamer GStreamer vulnerability
An invalid memory read in the glib function gtypecheckinstanceisfundamentallya was found caused by calling unref() on a reference owned by the caller function.
Upstream bug:
https://bugzilla.gnome.org/showbug.cgi?id=774897
CVE assignment:
http://seclists.org/oss-sec/2016/q4/589
Other sources
The gstdecodechainfreeinternal function in the flxdex decoder in gst-plugins-good in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (invalid memory read and crash) via an invalid file, which triggers an incorrect unref call.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9810?
CVE-2016-9810 has a severity rating that indicates it poses a denial of service risk due to potential crashes from invalid memory reads.
How do I fix CVE-2016-9810?
To fix CVE-2016-9810, it is recommended to upgrade GStreamer to version 1.10.2 or later.
What versions of GStreamer are affected by CVE-2016-9810?
CVE-2016-9810 affects GStreamer versions prior to 1.10.2 and specifically versions up to 1.8.
What types of attacks can exploit CVE-2016-9810?
CVE-2016-9810 can be exploited by remote attackers through the use of invalid files that trigger a denial of service.
Is CVE-2016-9810 related to any specific GStreamer components?
Yes, CVE-2016-9810 is related to the flxdex decoder in the gst-plugins-good component of GStreamer.