CVE-2016-9446
published 2017-01-23CVE-2016-9446: The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated by…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
3.57%
88.1th percentile
The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated by thumbnailing a simple 1 frame vmnc movie that does not draw to the allocated render canvas.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gst-plugins-bad1.0 | < gst-plugins-bad1.0 1.10.1-1 (bookworm) | gst-plugins-bad1.0 1.10.1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| gstreamer | gstreamer | < 1.11.1 | 1.11.1 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
gstreamer-plugins-bad-free: Missing initialization of allocated heap memory leads to information leak
vendor_redhat·2016-11-15·CVSS 7.5
CVE-2016-9446 [HIGH] CWE-456 gstreamer-plugins-bad-free: Missing initialization of allocated heap memory leads to information leak
gstreamer-plugins-bad-free: Missing initialization of allocated heap memory leads to information leak
The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated by thumbnailing a simple 1 frame vmnc movie that does not draw to the allocated render canvas.
Package: gstreamer-plugins-bad-free (Red Hat Enterprise Linux 6) - Will not fix
Package: mingw-gstreamer-plugins-bad-free (Red Hat Enterprise Virtualization 3) - Will not fix
Debian
CVE-2016-9446: gst-plugins-bad1.0 - The vmnc decoder in the gstreamer does not initialize the render canvas, which a...
vendor_debian·2016·CVSS 7.5
CVE-2016-9446 [HIGH] CVE-2016-9446: gst-plugins-bad1.0 - The vmnc decoder in the gstreamer does not initialize the render canvas, which a...
The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated by thumbnailing a simple 1 frame vmnc movie that does not draw to the allocated render canvas.
Scope: local
bookworm: resolved (fixed in 1.10.1-1)
bullseye: resolved (fixed in 1.10.1-1)
forky: resolved (fixed in 1.10.1-1)
sid: resolved (fixed in 1.10.1-1)
trixie: resolved (fixed in 1.10.1-1)
GHSA
GHSA-3xp5-mpvc-wqpw: The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated
ghsa_unreviewed·2022-05-13
CVE-2016-9446 [HIGH] CWE-665 GHSA-3xp5-mpvc-wqpw: The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated
The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated by thumbnailing a simple 1 frame vmnc movie that does not draw to the allocated render canvas.
OSV
CVE-2016-9446: The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated
osv·2017-01-23·CVSS 7.5
CVE-2016-9446 [HIGH] CVE-2016-9446: The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated
The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated by thumbnailing a simple 1 frame vmnc movie that does not draw to the allocated render canvas.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9446 mingw-gstreamer1: gstreamer: Missing initialization of allocated heap memory leads to information leak [epel-7]
bugzilla·2016-11-21·CVSS 7.5
CVE-2016-9446 [HIGH] CVE-2016-9446 mingw-gstreamer1: gstreamer: Missing initialization of allocated heap memory leads to information leak [epel-7]
CVE-2016-9446 mingw-gstreamer1: gstreamer: Missing initialization of allocated heap memory leads to information leak [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bu
Bugzilla
CVE-2016-9446 gstreamer: Missing initialization of allocated heap memory leads to information leak [fedora-all]
bugzilla·2016-11-21·CVSS 7.5
CVE-2016-9446 [HIGH] CVE-2016-9446 gstreamer: Missing initialization of allocated heap memory leads to information leak [fedora-all]
CVE-2016-9446 gstreamer: Missing initialization of allocated heap memory leads to information leak [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affec
Bugzilla
CVE-2016-9446 mingw-gstreamer: gstreamer: Missing initialization of allocated heap memory leads to information leak [fedora-all]
bugzilla·2016-11-21·CVSS 7.5
CVE-2016-9446 [HIGH] CVE-2016-9446 mingw-gstreamer: gstreamer: Missing initialization of allocated heap memory leads to information leak [fedora-all]
CVE-2016-9446 mingw-gstreamer: gstreamer: Missing initialization of allocated heap memory leads to information leak [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE:
Bugzilla
CVE-2016-9446 gstreamer1: gstreamer: Missing initialization of allocated heap memory leads to information leak [fedora-all]
bugzilla·2016-11-21·CVSS 7.5
CVE-2016-9446 [HIGH] CVE-2016-9446 gstreamer1: gstreamer: Missing initialization of allocated heap memory leads to information leak [fedora-all]
CVE-2016-9446 gstreamer1: gstreamer: Missing initialization of allocated heap memory leads to information leak [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this
Bugzilla
CVE-2016-9446 mingw-gstreamer1: gstreamer: Missing initialization of allocated heap memory leads to information leak [fedora-all]
bugzilla·2016-11-21·CVSS 7.5
CVE-2016-9446 [HIGH] CVE-2016-9446 mingw-gstreamer1: gstreamer: Missing initialization of allocated heap memory leads to information leak [fedora-all]
CVE-2016-9446 mingw-gstreamer1: gstreamer: Missing initialization of allocated heap memory leads to information leak [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE
Bugzilla
CVE-2016-9446 gstreamer-plugins-bad-free: Missing initialization of allocated heap memory leads to information leak
bugzilla·2016-11-21·CVSS 7.5
CVE-2016-9446 [HIGH] CVE-2016-9446 gstreamer-plugins-bad-free: Missing initialization of allocated heap memory leads to information leak
CVE-2016-9446 gstreamer-plugins-bad-free: Missing initialization of allocated heap memory leads to information leak
A missing initialization of allocated heap memory for render canvas leads to information leak.
CVE assignment:
http://seclists.org/oss-sec/2016/q4/462
External References:
https://scarybeastsecurity.blogspot.sk/2016/11/0day-poc-risky-design-decisions-in.html
Discussion:
Created mingw-gstreamer1 tracking bugs for this issue:
Affects: fedora-all [bug 1397067]
Affects: epel-7 [bug 1397068]
---
Created gstreamer tracking bugs for this issue:
Affects: fedora-all [bug 1397064]
---
Created mingw-gstreamer tracking bugs for this issue:
Affects: fedora-all [bug 1397066]
---
Created gstreamer1 tracking bugs for this issue:
Affects: fedora-all [bug 1397065]
---
Upstre
http://www.openwall.com/lists/oss-security/2016/11/18/12http://www.openwall.com/lists/oss-security/2016/11/18/13http://www.securityfocus.com/bid/94423https://access.redhat.com/errata/RHSA-2017:2060https://bugzilla.gnome.org/show_bug.cgi?id=774533https://cgit.freedesktop.org/gstreamer/gst-plugins-bad/commit/gst/vmnc/vmncdec.c?id=4cb1bcf1422bbcd79c0f683edb7ee85e3f7a31fehttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UM7IXFGHV66KNWGWG6ZBDNKXD2UJL2VQ/https://scarybeastsecurity.blogspot.de/2016/11/0day-poc-risky-design-decisions-in.htmlhttps://security.gentoo.org/glsa/201705-10http://www.openwall.com/lists/oss-security/2016/11/18/12http://www.openwall.com/lists/oss-security/2016/11/18/13http://www.securityfocus.com/bid/94423https://access.redhat.com/errata/RHSA-2017:2060https://bugzilla.gnome.org/show_bug.cgi?id=774533https://cgit.freedesktop.org/gstreamer/gst-plugins-bad/commit/gst/vmnc/vmncdec.c?id=4cb1bcf1422bbcd79c0f683edb7ee85e3f7a31fehttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UM7IXFGHV66KNWGWG6ZBDNKXD2UJL2VQ/https://scarybeastsecurity.blogspot.de/2016/11/0day-poc-risky-design-decisions-in.htmlhttps://security.gentoo.org/glsa/201705-10
2017-01-23
Published