MGASA-2016-0424

Source
https://advisories.mageia.org/MGASA-2016-0424.html
Import Source
https://advisories.mageia.org/MGASA-2016-0424.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2016-0424
Related
Published
2016-12-29T10:29:11Z
Modified
2016-12-29T10:16:35Z
Summary
Updated gstreamer0.10-plugins-good and gstreamer1.0-plugins-good packages fix security vulnerabilities
Details

Multiple flaws were discovered in GStreamer's FLC/FLI/FLX media file format decoding plug-in. A remote attacker could use these flaws to cause an application using GStreamer to crash or, potentially, execute arbitrary code with the privileges of the user running the application (CVE-2016-9634, CVE-2016-9635, CVE-2016-9636, CVE-2016-9808).

An invalid memory read access flaw was found in GStreamer's FLC/FLI/FLX media file format decoding plug-in. A remote attacker could use this flaw to cause an application using GStreamer to crash (CVE-2016-9807, CVE-2016-9810).

Note that CVE-2016-9810 only affected gstreamer1.0-plugins-good.

References
Credits

Affected packages