Junglewise Threat Intelligence

CVE-2016-9445: GStreamer integer overflow in vmnc decoder

CVE-2016-9445 · Severity: high · CVSS 7.5 · Published 2017-01-23

Technologies: Gstreamer, Red Hat Gstreamer-Plugins-Bad-Free. Vendors: Gstreamer, Red Hat.

Executive brief

GStreamer is a widely used multimedia framework that allows applications to play and process video and audio files. A vulnerability in its VMware video decoding component allows a remote attacker to crash applications using the library or potentially execute unauthorized code. This could lead to service disruptions or a full system compromise if a user opens a specially crafted video file.

Technical details

An integer overflow vulnerability exists in the vmnc (VMware VMnc) decoder within the GStreamer 'bad' plugins package. The flaw occurs when the decoder processes video files with excessively large width and height values, leading to an incorrect memory allocation size for the render buffer. This results in a heap-based buffer overflow. A remote attacker can exploit this by providing a malicious video file to an application using GStreamer, potentially achieving arbitrary code execution or causing a denial of service (crash). The vulnerability was addressed in GStreamer's vmncdec.c and various Linux distribution updates.

Affected products

  • GStreamer Project GStreamer 1.10.0
  • Red Hat gstreamer-plugins-bad-free Enterprise Linux 6, Enterprise Linux 7

Timeline

  • 2016-11-18: disclosed: Initial public disclosure via oss-security mailing list
  • 2016-12-21: patched: Red Hat released security updates for RHEL 6
  • 2017-01-05: patched: Red Hat released security updates for RHEL 7
  • 2017-01-23: advisory: NVD publication date

References

Related threats