First published: Mon Feb 06 2017(Updated: )
An out-of-bounds read in gst_date_time_new_from_iso8601_string() was found that can be triggered by malformed datetime string. Upstream bug: <a href="https://bugzilla.gnome.org/show_bug.cgi?id=777263">https://bugzilla.gnome.org/show_bug.cgi?id=777263</a> Upstream patch: <a href="https://github.com/GStreamer/gstreamer/commit/9398b7f1a75b38844ae7050b5a7967e4cdebe24f">https://github.com/GStreamer/gstreamer/commit/9398b7f1a75b38844ae7050b5a7967e4cdebe24f</a> CVE assignment: <a href="http://seclists.org/oss-sec/2017/q1/284">http://seclists.org/oss-sec/2017/q1/284</a>
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Gstreamer Project Gstreamer | <=1.10.2 | |
ubuntu/gstreamer1.0 | <1.10.3-1 | 1.10.3-1 |
ubuntu/gstreamer1.0 | <1.8.3-1~ubuntu0.1+ | 1.8.3-1~ubuntu0.1+ |
redhat/gstreamer1 | <1.10.3 | 1.10.3 |
debian/gstreamer1.0 | 1.14.4-1 1.18.4-2.1 1.22.0-2 1.22.10-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.