Back

CRITICAL

gstreamer-plugins-good: Heap buffer overflow in FLIC decoder

Published Jan 27, 2017

Description

Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by providing a 'skip count' that goes beyond initialized buffer.

Affected products

Remediation

Red Hat mitigation

This mitigation is only required if vulnerable gstreamer-plugins-good and/or gstreamer1-plugins-good packages are installed. For RHEL 7, sudo rm /usr/lib*/gstreamer-1.0/libgstflxdec.so sudo rm /usr/lib*/gstreamer-0.10/libgstflxdec.so For RHEL 5 and RHEL 6, sudo rm /usr/lib*/gstreamer-0.10/libgstflxdec.so Please note that this mitigation deletes the vulnerable FLI/FLC/FLX animation demuxer file(s), which removes the functionality to play FLI/FLC/FLX animation files.

Metrics

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 27, 2017
Updated Aug 6, 2024
Reserved Nov 23, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Nov 21, 2016