CVE-2016-9813: Null Pointer Dereference
Published Jan 13, 2017
·Updated
The parsepat function in the mpegts parser in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted file.
Affected Software
1 affected component
GStreamer GStreamer<=1.10.1
Event History
Jan 13, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-9813?
CVE-2016-9813 has a severity level that can lead to denial of service due to a NULL pointer dereference.
2
How do I fix CVE-2016-9813?
To fix CVE-2016-9813, upgrade GStreamer to version 1.10.2 or later.
3
Which versions of GStreamer are affected by CVE-2016-9813?
GStreamer versions before 1.10.2, specifically up to and including 1.10.1, are affected by CVE-2016-9813.
4
What kind of attack does CVE-2016-9813 enable?
CVE-2016-9813 allows remote attackers to conduct denial of service attacks against systems using the affected GStreamer versions.
5
Is CVE-2016-9813 a critical vulnerability?
While CVE-2016-9813 is not categorized as critical, it can still result in significant service disruption.