VDB

GCVE-VVD-MAGEIA-2018-12

GCVE-VVD-MAGEIA-2018-12
Advisory Published
Vulnetix · Advisory published January 11, 2018
Chris Evans discovered that the GStreamer plugin to decode VMware screen capture files allowed the execution of arbitrary code (CVE-2016-9445, CVE-2016-9446). Chris Evans discovered that the GStreamer 0.10 plugin to decode NES Sound Format files allowed the execution of arbitrary code (CVE-2016-9447). Hanno Boeck discovered multiple vulnerabilities in the GStreamer media framework and its codecs and demuxers, which may result in denial of service or the execution of arbitrary code if a malformed media file is opened (CVE-2016-9809, CVE-2016-9812, CVE-2016-9813, CVE-2017-5843, CVE-2017-5848). The gstreamer0.10-plugins-bad package was affected by CVE-2016-9445, CVE-2016-9446, CVE-2016-9447, CVE-2016-9809, CVE-2017-5843, and CVE-2017-5848). The gstreamer1.0-plugins-bad package was affected by CVE-2016-9445, CVE-2016-9446, CVE-2016-9809, CVE-2016-9812, CVE-2016-9813, CVE-2017-5843, and CVE-2017-5848.

Affected Products

VendorProductVersionsPlatforms
Mageiaemerald0 (affected), 0.8.14-1.mga6 (unaffected)
Mageiagstreamer1.0-plugins-bad0 (affected), 1.4.3-2.1.mga5 (unaffected), 0 (affected), 1.4.3-2.1.mga5.tainted (unaffected), 0 (affected), 1.4.3-2.1.mga5 (unaffected), 0 (affected), 1.4.3-2.1.mga5.tainted (unaffected)
Mageiagstreamer0.10-plugins-bad0 (affected), 0.10.23-22.2.mga5 (unaffected), 0 (affected), 0.10.23-22.2.mga5.tainted (unaffected), 0 (affected), 0.10.23-22.2.mga5 (unaffected), 0 (affected), 0.10.23-22.2.mga5.tainted (unaffected)

References

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›