Description
The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated by thumbnailing a simple 1 frame vmnc movie that does not draw to the allocated render canvas.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-712-1 | gst-plugins-bad0.10 security update |
EUVD |
EUVD-2016-10256 | The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated by thumbnailing a simple 1 frame vmnc movie that does not draw to the allocated render canvas. |
References
History
Tue, 17 Mar 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gstreamer
Gstreamer gstreamer |
|
| CPEs | cpe:2.3:a:gstreamer:gstreamer:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gstreamer Project
Gstreamer Project gstreamer |
Gstreamer
Gstreamer gstreamer |
Subscriptions
Fedoraproject
Subscribe
Fedora
Subscribe
Gstreamer
Subscribe
Gstreamer
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Enterprise Linux Desktop
Subscribe
Enterprise Linux Eus
Subscribe
Enterprise Linux Server
Subscribe
Enterprise Linux Server Aus
Subscribe
Enterprise Linux Server Tus
Subscribe
Enterprise Linux Workstation
Subscribe
Status: PUBLISHED
Assigner: microfocus
Published:
Updated: 2024-08-06T02:50:38.682Z
Reserved: 2016-11-18T00:00:00.000Z
Link: CVE-2016-9446
No data.
Status : Deferred
Published: 2017-01-23T21:59:03.063
Modified: 2026-03-17T15:52:33.870
Link: CVE-2016-9446
OpenCVE Enrichment
No data.
Debian DLA
EUVD