CVE-2016-10199

Priority
Low
Description
The qtdemux_tag_add_str_full function in gst/isomp4/qtdemux.c in
gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to
cause a denial of service (out-of-bounds read and crash) via a crafted tag
value.
References
Bugs
Package
Upstream:needed
Ubuntu 17.10 (Artful Aardvark):DNE
Ubuntu 12.04 ESM (Precise Pangolin):DNE (precise was released [0.10.31-1ubuntu1.5])
Ubuntu 14.04 LTS (Trusty Tahr):released (0.10.31-3+nmu1ubuntu5.3)
Ubuntu Touch 15.04:ignored (reached end-of-life)
Ubuntu Core 15.04:DNE
Ubuntu 16.04 LTS (Xenial Xerus):released (0.10.31-3+nmu4ubuntu2.16.04.3)
Ubuntu 16.10 (Yakkety Yak):DNE
Ubuntu 17.04 (Zesty Zapus):DNE
Package
Upstream:released (1.10.3-1)
Ubuntu 17.10 (Artful Aardvark):not-affected (1.10.3-1ubuntu1)
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 LTS (Trusty Tahr):released (1.2.4-1~ubuntu1.4)
Ubuntu Touch 15.04:ignored (reached end-of-life)
Ubuntu Core 15.04:DNE
Ubuntu 16.04 LTS (Xenial Xerus):released (1.8.3-1ubuntu0.4)
Ubuntu 16.10 (Yakkety Yak):released (1.8.3-1ubuntu1.3)
Ubuntu 17.04 (Zesty Zapus):not-affected (1.10.3-1ubuntu1)
Patches:
Upstream:https://github.com/GStreamer/gst-plugins-good/commit/d0949baf3dadea6021d54abef6802fed5a06af75
More Information

Updated: 2017-06-15 16:17:44 UTC (commit 12747)