Junglewise Threat Intelligence

CVE-2016-9447: GStreamer NSF decoder memory corruption in ROM mappings

CVE-2016-9447 · Severity: high · CVSS 7.8 · Published 2017-01-23

Technologies: Red Hat Gstreamer-Plugins-Bad-Free. Vendors: Red Hat.

Executive brief

GStreamer, a widely used multimedia framework for processing audio and video, contains a security vulnerability in its Nintendo NSF music file decoder. By tricking a user into opening a specially crafted music file, an attacker could cause the application to crash or potentially execute malicious code on the user's system. This could lead to a full system compromise or unauthorized access to the user's data.

Technical details

A memory corruption flaw exists in the Nintendo NSF music file format decoding plug-in within GStreamer 0.10.x (specifically in the gstreamer-plugins-bad-free package). The vulnerability is caused by improper ROM mapping handling, leading to out-of-bounds read or write operations. An attacker can exploit this by providing a malformed NSF file that, when processed by the decoder, triggers the memory corruption. This can result in an application crash (DoS) or arbitrary code execution with the privileges of the user. Red Hat addressed this by removing the vulnerable NSF plug-in entirely in affected versions of RHEL 6 and 7.

Affected products

  • GStreamer Project GStreamer 0.10.x
  • Red Hat gstreamer-plugins-bad-free Enterprise Linux 6, Enterprise Linux 7

Timeline

  • 2016-12-21: advisory: Red Hat issued RHSA-2016:2974 for RHEL 6
  • 2017-01-05: advisory: Red Hat issued RHSA-2017:0018 for RHEL 7
  • 2017-01-23: disclosed: NVD publication date

References

Related threats