A vulnerability was found in gstreamer-0.10. There is a near total lack of bounds checking on proposed ROM mappings. This applies to be the initial ROM load, as well as subsequent ROM bank switching. All of the handling for ROM mapping is in gst-plugins-bad/gst/nsf.c External References: https://scarybeastsecurity.blogspot.cz/2016/11/0day-exploit-compromising-linux-desktop.html
Created gstreamer tracking bugs for this issue: Affects: fedora-all [bug 1395128]
Created mingw-gstreamer tracking bugs for this issue: Affects: fedora-all [bug 1395129]
Mitigation: sudo rm /usr/lib*/gstreamer-0.10/libgstnsf.so Please note that this mitigation deletes the vulnerable NSF codec file, which removes the functionality to play Nintendo NSF music files.
CVE assignment: http://seclists.org/oss-sec/2016/q4/462
Created gstreamer-plugins-bad-free tracking bugs for this issue: Affects: fedora-all [bug 1400908]
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Via RHSA-2016:2974 https://rhn.redhat.com/errata/RHSA-2016-2974.html
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2017:0018 https://rhn.redhat.com/errata/RHSA-2017-0018.html