« List of all CVEs

CVE-2016-9446

Published: 1/23/2017 Last updated: 8/6/2024 Reserved: 11/18/2016

The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated by thumbnailing a simple 1 frame vmnc movie that does not draw to the allocated render canvas.

CNA assigner: microfocus (f81092c5-7f14-476d-80dc-24857f90be84) Requested by: n/a

Opam packages affected (2)

conf-gstreamer gstreamer

Products affected (1)

Product Vendor Version
n/a n/a n/a

References (18)