4.7
CVSSv3

CVE-2016-9811

Published: 13/01/2017 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 4.7 | Impact Score: 3.6 | Exploitability Score: 1
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The windows_icon_typefind function in gst-plugins-base in GStreamer prior to 1.10.2, when G_SLICE is set to always-malloc, allows remote malicious users to cause a denial of service (out-of-bounds read) via a crafted ico file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gstreamer gstreamer

fedoraproject fedora 35

debian debian linux 8.0

debian debian linux 9.0

redhat enterprise linux desktop 7.0

redhat enterprise linux workstation 7.0

redhat enterprise linux server 7.0

redhat enterprise linux server aus 7.4

redhat enterprise linux eus 7.4

redhat enterprise linux eus 7.5

redhat enterprise linux server tus 7.6

redhat enterprise linux server aus 7.6

redhat enterprise linux eus 7.6

redhat enterprise linux server aus 7.7

redhat enterprise linux server tus 7.7

redhat enterprise linux eus 7.7

Vendor Advisories

GStreamer Base Plugins could be made to crash if it opened a specially crafted file ...
The windows_icon_typefind function in gst-plugins-base in GStreamer before 1102, when G_SLICE is set to always-malloc, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted ico file ...