ZeroHour

CVE-2016-9446

CVSS 3.1
7.5 high
EPSS
4%p89
Published
()
Modified
Description

The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated by thumbnailing a simple 1 frame vmnc movie that does not draw to the allocated render canvas.

Vendors
gstreamerredhatfedoraproject
Products
gstreamer, enterprise linux desktop, enterprise linux eus, enterprise linux server, enterprise linux server aus, enterprise linux server tus, enterprise linux workstation, fedora
Weakness
CWE-665
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.