The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated by thumbnailing a simple 1 frame vmnc movie that does not draw to the allocated render canvas.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: microfocus
Published: 2017-01-23T21:00:00
Updated: 2024-08-06T02:50:38.682Z
Reserved: 2016-11-18T00:00:00
Link: CVE-2016-9446
Vulnrichment
No data.
NVD
Status : Modified
Published: 2017-01-23T21:59:03.063
Modified: 2023-11-07T02:37:02.890
Link: CVE-2016-9446
Redhat