CVE-2016-10198

Priority
Low
Description
The gst_aac_parse_sink_setcaps function in gst/audioparsers/gstaacparse.c
in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to
cause a denial of service (invalid memory read and crash) via a crafted
audio file.
References
Bugs
Package
Upstream:needed
Ubuntu 17.10 (Artful Aardvark):DNE
Ubuntu 12.04 ESM (Precise Pangolin):DNE (precise was released [0.10.31-1ubuntu1.5])
Ubuntu 14.04 LTS (Trusty Tahr):released (0.10.31-3+nmu1ubuntu5.3)
Ubuntu Core 15.04:DNE
Ubuntu 16.04 LTS (Xenial Xerus):released (0.10.31-3+nmu4ubuntu2.16.04.3)
Ubuntu 17.04 (Zesty Zapus):DNE
Package
Upstream:released (1.10.3-1)
Ubuntu 17.10 (Artful Aardvark):not-affected (1.10.3-1ubuntu1)
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 LTS (Trusty Tahr):released (1.2.4-1~ubuntu1.4)
Ubuntu Core 15.04:DNE
Ubuntu 16.04 LTS (Xenial Xerus):released (1.8.3-1ubuntu0.4)
Ubuntu 17.04 (Zesty Zapus):not-affected (1.10.3-1ubuntu1)
Patches:
Upstream:https://github.com/GStreamer/gst-plugins-good/commit/87a2c140ca54c5128093377e9b25a5c24b346727
More Information

Updated: 2017-08-11 23:54:19 UTC (commit 13081)