Chris Evans discovered that the GStreamer plugin to decode VMware screen capture files allowed the execution of arbitrary code (CVE-2016-9445, CVE-2016-9446).
Chris Evans discovered that the GStreamer 0.10 plugin to decode NES Sound Format files allowed the execution of arbitrary code (CVE-2016-9447).
Hanno Boeck discovered multiple vulnerabilities in the GStreamer media framework and its codecs and demuxers, which may result in denial of service or the execution of arbitrary code if a malformed media file is opened (CVE-2016-9809, CVE-2016-9812, CVE-2016-9813, CVE-2017-5843, CVE-2017-5848).
The gstreamer0.10-plugins-bad package was affected by CVE-2016-9445, CVE-2016-9446, CVE-2016-9447, CVE-2016-9809, CVE-2017-5843, and CVE-2017-5848).
The gstreamer1.0-plugins-bad package was affected by CVE-2016-9445, CVE-2016-9446, CVE-2016-9809, CVE-2016-9812, CVE-2016-9813, CVE-2017-5843, and CVE-2017-5848.