Back

HIGH

gstreamer-plugins-bad-free: Memory corruption flaw in NSF decoder

Published Jan 23, 2017

Description

The ROM mappings in the NSF decoder in gstreamer 0.10.x allow remote attackers to cause a denial of service (out-of-bounds read or write) and possibly execute arbitrary code via a crafted NSF music file.

Affected products

Remediation

Red Hat mitigation

sudo rm /usr/lib*/gstreamer-0.10/libgstnsf.so Please note that this mitigation deletes the vulnerable NSF codec file, which removes the functionality to play Nintendo NSF music files.

Metrics

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner microfocus
Published Jan 23, 2017
Updated Aug 6, 2024
Reserved Nov 18, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Nov 14, 2016