Description
The _parse_pat function in the mpegts parser in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted file.
In plain language
AI Worth attentionIf your business uses GStreamer versions before 1.10.2, a specially crafted video file can make the program crash when a user opens it—this is usually only a risk if someone can trick your staff into viewing that file.
In GStreamer before 1.10.2, the mpegts parser’s _parse_pat handling can dereference a NULL pointer when processing a crafted media file, allowing remote attackers to trigger a denial-of-service crash via user-opening of the file.
What to do now
- Check your installed GStreamer version(s) and confirm whether any are earlier than 1.10.2.
- Update GStreamer to 1.10.2 or later using your normal software update method.
- If you cannot update right away, prevent staff from opening or previewing media from untrusted sources until patched.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:NConfidentialityI:NIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2016-9813 and every CVE in our database. Create a free account — no credit card required.
Create Free Account