CVE-2016-9811

Priority
Low
Description
The windows_icon_typefind function in gst-plugins-base in GStreamer before
1.10.2, when G_SLICE is set to always-malloc, allows remote attackers to
cause a denial of service (out-of-bounds read) via a crafted ico file.
References
Bugs
Package
Upstream:needs-triage
Ubuntu 17.10 (Artful Aardvark):DNE
Ubuntu 12.04 ESM (Precise Pangolin):DNE (precise was released [0.10.36-1ubuntu0.2])
Ubuntu 14.04 LTS (Trusty Tahr):released (0.10.36-1.1ubuntu2.1)
Ubuntu Touch 15.04:ignored (reached end-of-life)
Ubuntu Core 15.04:DNE
Ubuntu 16.04 LTS (Xenial Xerus):released (0.10.36-2ubuntu0.1)
Ubuntu 16.10 (Yakkety Yak):DNE
Ubuntu 17.04 (Zesty Zapus):DNE
Package
Upstream:released (1.10.2-1)
Ubuntu 17.10 (Artful Aardvark):not-affected (1.10.2-1ubuntu1)
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 LTS (Trusty Tahr):released (1.2.4-1~ubuntu2.1)
Ubuntu Touch 15.04:ignored (reached end-of-life)
Ubuntu Core 15.04:DNE
Ubuntu 16.04 LTS (Xenial Xerus):released (1.8.3-1ubuntu0.2)
Ubuntu 16.10 (Yakkety Yak):released (1.8.3-1ubuntu1.1)
Ubuntu 17.04 (Zesty Zapus):not-affected (1.10.2-1ubuntu1)
Patches:
Upstream:https://github.com/GStreamer/gst-plugins-base/commit/2fdccfd64fc609e44e9c4b8eed5bfdc0ab9c9095
More Information

Updated: 2017-06-15 16:17:56 UTC (commit 12747)