CVE-2016-9447

The ROM mappings in the NSF decoder in gstreamer 0.10.x allow remote attackers to cause a denial of service (out-of-bounds read or write) and possibly execute arbitrary code via a crafted NSF music file.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
gstreamergstreamer
0.10.0
gstreamergstreamer
0.10.1
gstreamergstreamer
0.10.2
gstreamergstreamer
0.10.3
gstreamergstreamer
0.10.4
gstreamergstreamer
0.10.5
gstreamergstreamer
0.10.6
gstreamergstreamer
0.10.7
gstreamergstreamer
0.10.8
gstreamergstreamer
0.10.9
gstreamergstreamer
0.10.10
gstreamergstreamer
0.10.11
gstreamergstreamer
0.10.12
gstreamergstreamer
0.10.13
gstreamergstreamer
0.10.14
gstreamergstreamer
0.10.15
gstreamergstreamer
0.10.16
gstreamergstreamer
0.10.17
gstreamergstreamer
0.10.18
gstreamergstreamer
0.10.19
gstreamergstreamer
0.10.20
gstreamergstreamer
0.10.21
gstreamergstreamer
0.10.22
gstreamergstreamer
0.10.23
gstreamergstreamer
0.10.24
gstreamergstreamer
0.10.25
gstreamergstreamer
0.10.26
gstreamergstreamer
0.10.27
gstreamergstreamer
0.10.28
gstreamergstreamer
0.10.29
gstreamergstreamer
0.10.30
gstreamergstreamer
0.10.31
gstreamergstreamer
0.10.32
gstreamergstreamer
0.10.33
gstreamergstreamer
0.10.34
gstreamergstreamer
0.10.35
gstreamergstreamer
0.10.36
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gst-plugins-bad0.10
precise
Fixed 0.10.22.3-2ubuntu2.4
released
trusty
Fixed 0.10.23-7.2ubuntu1.2
released
xenial
dne
yakkety
dne