CVE-2016-9447

EUVD-2016-10257
The ROM mappings in the NSF decoder in gstreamer 0.10.x allow remote attackers to cause a denial of service (out-of-bounds read or write) and possibly execute arbitrary code via a crafted NSF music file.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 64%
Affected Products (NVD)
VendorProductVersion
gstreamer_projectgstreamer
0.10.0
gstreamer_projectgstreamer
0.10.1
gstreamer_projectgstreamer
0.10.2
gstreamer_projectgstreamer
0.10.3
gstreamer_projectgstreamer
0.10.4
gstreamer_projectgstreamer
0.10.5
gstreamer_projectgstreamer
0.10.6
gstreamer_projectgstreamer
0.10.7
gstreamer_projectgstreamer
0.10.8
gstreamer_projectgstreamer
0.10.9
gstreamer_projectgstreamer
0.10.10
gstreamer_projectgstreamer
0.10.11
gstreamer_projectgstreamer
0.10.12
gstreamer_projectgstreamer
0.10.13
gstreamer_projectgstreamer
0.10.14
gstreamer_projectgstreamer
0.10.15
gstreamer_projectgstreamer
0.10.16
gstreamer_projectgstreamer
0.10.17
gstreamer_projectgstreamer
0.10.18
gstreamer_projectgstreamer
0.10.19
gstreamer_projectgstreamer
0.10.20
gstreamer_projectgstreamer
0.10.21
gstreamer_projectgstreamer
0.10.22
gstreamer_projectgstreamer
0.10.23
gstreamer_projectgstreamer
0.10.24
gstreamer_projectgstreamer
0.10.25
gstreamer_projectgstreamer
0.10.26
gstreamer_projectgstreamer
0.10.27
gstreamer_projectgstreamer
0.10.28
gstreamer_projectgstreamer
0.10.29
gstreamer_projectgstreamer
0.10.30
gstreamer_projectgstreamer
0.10.31
gstreamer_projectgstreamer
0.10.32
gstreamer_projectgstreamer
0.10.33
gstreamer_projectgstreamer
0.10.34
gstreamer_projectgstreamer
0.10.35
gstreamer_projectgstreamer
0.10.36
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gst-plugins-bad0.10
precise
Fixed 0.10.22.3-2ubuntu2.4
released
trusty
Fixed 0.10.23-7.2ubuntu1.2
released
xenial
dne
yakkety
dne