CVE-2016-9811
published 2017-01-13CVE-2016-9811: The windows_icon_typefind function in gst-plugins-base in GStreamer before 1.10.2, when G_SLICE is set to always-malloc, allows remote attackers to cause a…
PriorityP418medium4.7CVSS 3.1
AVLACHPRNUIRSUCNINAH
EPSS
2.36%
81.9th percentile
The windows_icon_typefind function in gst-plugins-base in GStreamer before 1.10.2, when G_SLICE is set to always-malloc, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted ico file.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | gst-plugins-base1.0 | < gst-plugins-base1.0 1.10.2-1 (bookworm) | gst-plugins-base1.0 1.10.2-1 (bookworm) |
| fedoraproject | fedora | — | — |
| gstreamer | gstreamer | <= 1.10.1 | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.7MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f9mv-78h4-x2jx: The windows_icon_typefind function in gst-plugins-base in GStreamer before 1
ghsa_unreviewed·2022-05-13
CVE-2016-9811 [MEDIUM] CWE-125 GHSA-f9mv-78h4-x2jx: The windows_icon_typefind function in gst-plugins-base in GStreamer before 1
The windows_icon_typefind function in gst-plugins-base in GStreamer before 1.10.2, when G_SLICE is set to always-malloc, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted ico file.
OSV
CVE-2016-9811: The windows_icon_typefind function in gst-plugins-base in GStreamer before 1
osv·2017-01-13·CVSS 4.7
CVE-2016-9811 [MEDIUM] CVE-2016-9811: The windows_icon_typefind function in gst-plugins-base in GStreamer before 1
The windows_icon_typefind function in gst-plugins-base in GStreamer before 1.10.2, when G_SLICE is set to always-malloc, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted ico file.
Ubuntu
GStreamer Base Plugins vulnerabilities
vendor_ubuntu·2017-03-27
CVE-2016-9811 GStreamer Base Plugins vulnerabilities
Title: GStreamer Base Plugins vulnerabilities
Summary: GStreamer Base Plugins could be made to crash if it opened a specially
crafted file.
Hanno Böck discovered that GStreamer Base Plugins did not correctly handle
certain malformed media files. If a user were tricked into opening a
crafted media file with a GStreamer application, an attacker could cause a
denial of service via application crash.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
gstreamer: Out of bounds heap read in windows_icon_typefind
vendor_redhat·2016-11-23·CVSS 4.7
CVE-2016-9811 [MEDIUM] CWE-125 gstreamer: Out of bounds heap read in windows_icon_typefind
gstreamer: Out of bounds heap read in windows_icon_typefind
The windows_icon_typefind function in gst-plugins-base in GStreamer before 1.10.2, when G_SLICE is set to always-malloc, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted ico file.
Package: gstreamer-plugins-base (Red Hat Enterprise Linux 5) - Not affected
Package: gstreamer-plugins-base (Red Hat Enterprise Linux 6) - Not affected
Package: gstreamer-plugins-base (Red Hat Enterprise Linux 7) - Will not fix
Package: mingw-virt-viewer (Red Hat Enterprise Virtualization 3) - Will not fix
Debian
CVE-2016-9811: gst-plugins-base1.0 - The windows_icon_typefind function in gst-plugins-base in GStreamer before 1.10....
vendor_debian·2016·CVSS 4.7
CVE-2016-9811 [MEDIUM] CVE-2016-9811: gst-plugins-base1.0 - The windows_icon_typefind function in gst-plugins-base in GStreamer before 1.10....
The windows_icon_typefind function in gst-plugins-base in GStreamer before 1.10.2, when G_SLICE is set to always-malloc, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted ico file.
Scope: local
bookworm: resolved (fixed in 1.10.2-1)
bullseye: resolved (fixed in 1.10.2-1)
forky: resolved (fixed in 1.10.2-1)
sid: resolved (fixed in 1.10.2-1)
trixie: resolved (fixed in 1.10.2-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9811 gstreamer1-plugins-base: gstreamer: Out of bounds heap read in windows_icon_typefind [fedora-all]
bugzilla·2016-12-06·CVSS 4.7
CVE-2016-9811 [MEDIUM] CVE-2016-9811 gstreamer1-plugins-base: gstreamer: Out of bounds heap read in windows_icon_typefind [fedora-all]
CVE-2016-9811 gstreamer1-plugins-base: gstreamer: Out of bounds heap read in windows_icon_typefind [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affec
Bugzilla
CVE-2016-9811 mingw-gstreamer1-plugins-base: gstreamer: Out of bounds heap read in windows_icon_typefind [fedora-all]
bugzilla·2016-12-06·CVSS 4.7
CVE-2016-9811 [MEDIUM] CVE-2016-9811 mingw-gstreamer1-plugins-base: gstreamer: Out of bounds heap read in windows_icon_typefind [fedora-all]
CVE-2016-9811 mingw-gstreamer1-plugins-base: gstreamer: Out of bounds heap read in windows_icon_typefind [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2016-9811 mingw-gstreamer-plugins-base: gstreamer: Out of bounds heap read in windows_icon_typefind [fedora-all]
bugzilla·2016-12-06·CVSS 4.7
CVE-2016-9811 [MEDIUM] CVE-2016-9811 mingw-gstreamer-plugins-base: gstreamer: Out of bounds heap read in windows_icon_typefind [fedora-all]
CVE-2016-9811 mingw-gstreamer-plugins-base: gstreamer: Out of bounds heap read in windows_icon_typefind [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2016-9811 gstreamer-plugins-base: gstreamer: Out of bounds heap read in windows_icon_typefind [fedora-all]
bugzilla·2016-12-06·CVSS 4.7
CVE-2016-9811 [MEDIUM] CVE-2016-9811 gstreamer-plugins-base: gstreamer: Out of bounds heap read in windows_icon_typefind [fedora-all]
CVE-2016-9811 gstreamer-plugins-base: gstreamer: Out of bounds heap read in windows_icon_typefind [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affect
Bugzilla
CVE-2016-9811 gstreamer: Out of bounds heap read in windows_icon_typefind
bugzilla·2016-12-06·CVSS 4.7
CVE-2016-9811 [MEDIUM] CVE-2016-9811 gstreamer: Out of bounds heap read in windows_icon_typefind
CVE-2016-9811 gstreamer: Out of bounds heap read in windows_icon_typefind
An out-of-bounds heap read was found in windows_icon_typefind.
Upstream bug:
https://bugzilla.gnome.org/show_bug.cgi?id=774902
Upstream patch:
https://github.com/GStreamer/gst-plugins-base/commit/2fdccfd64fc609e44e9c4b8eed5bfdc0ab9c9095
CVE assignment:
http://seclists.org/oss-sec/2016/q4/589
Discussion:
Created gstreamer1-plugins-base tracking bugs for this issue:
Affects: fedora-all [bug 1401950]
---
Created mingw-gstreamer1-plugins-base tracking bugs for this issue:
Affects: fedora-all [bug 1401952]
---
Created mingw-gstreamer-plugins-base tracking bugs for this issue:
Affects: fedora-all [bug 1401951]
---
Created gstreamer-plugins-base tracking bugs for this issue:
Affects: fedora-all [bug 14019
Bugzilla
CVE-2014-9811 ImageMagick: crash in xwd file handler
bugzilla·2016-06-07·CVSS 5.5
CVE-2014-9811 [MEDIUM] CVE-2014-9811 ImageMagick: crash in xwd file handler
CVE-2014-9811 ImageMagick: crash in xwd file handler
Fix a SEGV in malformed xwd file handler.
CVE assignment:
http://seclists.org/oss-sec/2016/q2/459
Upstream patches:
https://anonscm.debian.org/cgit/collab-maint/imagemagick.git/commit/?h=debian-patches/6.8.9.9-4-for-upstream&id=82a5bbdd47b9b3f43ce3c2aa18741aecc4a0f962
https://anonscm.debian.org/cgit/collab-maint/imagemagick.git/commit/?h=debian-patches/6.8.9.9-4-for-upstream&id=914da276f717b3e21e5af6614887af14af87a9b8
http://www.debian.org/security/2017/dsa-3819http://www.openwall.com/lists/oss-security/2016/12/01/2http://www.openwall.com/lists/oss-security/2016/12/05/8http://www.securityfocus.com/bid/95161https://access.redhat.com/errata/RHSA-2017:2060https://bugzilla.gnome.org/show_bug.cgi?id=774902https://gstreamer.freedesktop.org/releases/1.10/#1.10.2https://lists.debian.org/debian-lts-announce/2020/02/msg00032.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UM7IXFGHV66KNWGWG6ZBDNKXD2UJL2VQ/https://security.gentoo.org/glsa/201705-10http://www.debian.org/security/2017/dsa-3819http://www.openwall.com/lists/oss-security/2016/12/01/2http://www.openwall.com/lists/oss-security/2016/12/05/8http://www.securityfocus.com/bid/95161https://access.redhat.com/errata/RHSA-2017:2060https://bugzilla.gnome.org/show_bug.cgi?id=774902https://gstreamer.freedesktop.org/releases/1.10/#1.10.2https://lists.debian.org/debian-lts-announce/2020/02/msg00032.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UM7IXFGHV66KNWGWG6ZBDNKXD2UJL2VQ/https://security.gentoo.org/glsa/201705-10
2017-01-13
Published