Rapid7’s 2026 Global Cybersecurity Summit is now available on-demand.Watch sessions.
Rapid7

vulnerability

SUSE: CVE-2016-9809: SUSE Linux Security Advisory

Severity
7
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:P)
Published
Dec 29, 2016
Added
Dec 30, 2016
Modified
Aug 12, 2021

Description

Off-by-one error in the gst_h264_parse_set_caps function in GStreamer before 1.10.2 allows remote attackers to have unspecified impact via a crafted file, which triggers an out-of-bounds read.

Solutions

suse-upgrade-gstreamer-0_10-plugins-badsuse-upgrade-gstreamer-0_10-plugins-bad-develsuse-upgrade-gstreamer-0_10-plugins-bad-langsuse-upgrade-gstreamer-plugins-badsuse-upgrade-gstreamer-plugins-bad-develsuse-upgrade-gstreamer-plugins-bad-langsuse-upgrade-libgstadaptivedemux-1_0-0suse-upgrade-libgstbadaudio-1_0-0suse-upgrade-libgstbadbase-1_0-0suse-upgrade-libgstbadvideo-1_0-0suse-upgrade-libgstbasecamerabinsrc-0_10-23suse-upgrade-libgstbasecamerabinsrc-0_10-23-32bitsuse-upgrade-libgstbasecamerabinsrc-1_0-0suse-upgrade-libgstbasevideo-0_10-23suse-upgrade-libgstbasevideo-0_10-23-32bitsuse-upgrade-libgstcodecparsers-0_10-23suse-upgrade-libgstcodecparsers-1_0-0suse-upgrade-libgstegl-1_0-0suse-upgrade-libgstgl-1_0-0suse-upgrade-libgstinsertbin-1_0-0suse-upgrade-libgstmpegts-1_0-0suse-upgrade-libgstphotography-0_10-23suse-upgrade-libgstphotography-0_10-23-32bitsuse-upgrade-libgstphotography-1_0-0suse-upgrade-libgstsignalprocessor-0_10-23suse-upgrade-libgstsignalprocessor-0_10-23-32bitsuse-upgrade-libgsturidownloader-1_0-0suse-upgrade-libgstvdp-0_10-23suse-upgrade-libgstvdp-0_10-23-32bit

References

    Title
    Rapid7 Labs

    2026 Global Threat Landscape Report

    The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.