The gstavidemuxparsencdt function in gst/avi/gstavidemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (invalid memory read and crash) via a ncdt sub-tag that "goes behind" the surrounding tag.
{
"binaries": [
{
"binary_name": "gstreamer1.0-plugins-good",
"binary_version": "1.8.3-1ubuntu0.4"
},
{
"binary_name": "gstreamer1.0-pulseaudio",
"binary_version": "1.8.3-1ubuntu0.4"
},
{
"binary_name": "libgstreamer-plugins-good1.0-0",
"binary_version": "1.8.3-1ubuntu0.4"
},
{
"binary_name": "libgstreamer-plugins-good1.0-dev",
"binary_version": "1.8.3-1ubuntu0.4"
}
],
"availability": "No subscription required"
}