CVE-2016-9447

Advisory lineage Upstream: 0 Downstream: 8
Modified
Published: 23 Jan 2017, 21:00
Last modified:06 Aug 2024, 02:50

Vulnerability Summary

Overall Risk (default)
medium
31/100
CVSS Score
7.8 HIGH
v3.0 (nvd)
EPSS Score
0.48% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

23 Jan 2017, 21:00
Published
Vulnerability first disclosed
06 Aug 2024, 02:50
Last Modified
Vulnerability information updated

Description

The ROM mappings in the NSF decoder in gstreamer 0.10.x allow remote attackers to cause a denial of service (out-of-bounds read or write) and possibly execute arbitrary code via a crafted NSF music file.

CVSS Metrics

  • v3.0HIGHScore: 7.8CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  • v2.0MEDIUMScore: 6.8AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 0.48% Percentile: 66%

Techniques & Countermeasures

  • CWE-125Out-of-bounds Read

    The product reads data past the end, or before the beginning, of the intended buffer.

  • CWE-787Out-of-bounds Write

    The product writes data past the end, or before the beginning, of the intended buffer.

Affected Systems

  • gstreamer_projectgstreamer

    0.10.0 | 0.10.1 | 0.10.2 | 0.10.3 | 0.10.4 | 0.10.5 | 0.10.6 | 0.10.7 | 0.10.8 | 0.10.9 | 0.10.10 | 0.10.11 | 0.10.12 | 0.10.13 | 0.10.14 | 0.10.15 | 0.10.16 | 0.10.17 | 0.10.18 | 0.10.19 | 0.10.20 | 0.10.21 | 0.10.22 | 0.10.23 | 0.10.24 | 0.10.25 | 0.10.26 | 0.10.27 | 0.10.28 | 0.10.29 | 0.10.30 | 0.10.31 | 0.10.32 | 0.10.33 | 0.10.34 | 0.10.35 | 0.10.36

  • gstreamergstreamer

    0.10.0 | 0.10.1 | 0.10.2 | 0.10.3 | 0.10.4 | 0.10.5 | 0.10.6 | 0.10.7 | 0.10.8 | 0.10.9 | 0.10.10 | 0.10.11 | 0.10.12 | 0.10.13 | 0.10.14 | 0.10.15 | 0.10.16 | 0.10.17 | 0.10.18 | 0.10.19 | 0.10.20 | 0.10.21 | 0.10.22 | 0.10.23 | 0.10.24 | 0.10.25 | 0.10.26 | 0.10.27 | 0.10.28 | 0.10.29 | 0.10.30 | 0.10.31 | 0.10.32 | 0.10.33 | 0.10.34 | 0.10.35 | 0.10.36

References (7)