Back

HIGH

gstreamer-plugins-bad-free: Integer overflow when allocating render buffer in VMnc decoder

Published Jan 23, 2017

Description

Integer overflow in the vmnc decoder in the gstreamer allows remote attackers to cause a denial of service (crash) via large width and height values, which triggers a buffer overflow.

Affected products

Remediation

Red Hat mitigation

This mitigation is only required if vulnerable gstreamer-plugins-bad-free and/or gstreamer1-plugins-bad-free packages are installed. For RHEL 7, sudo rm /usr/lib*/gstreamer-1.0/libgstvmnc.so sudo rm /usr/lib*/gstreamer-0.10/libgstvmnc.so For RHEL 6, sudo rm /usr/lib*/gstreamer-0.10/libgstvmnc.so Please note that this mitigation deletes the vulnerable VMware NC decoder, which removes the functionality to play VMware movie files.

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner microfocus
Published Jan 23, 2017
Updated Aug 6, 2024
Reserved Nov 18, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Nov 15, 2016