The html_context_handle_element function in gst/subparse/samiparse.c in gst-plugins-base in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted SMI file, as demonstrated by OneNote_Manager.smi.
| Software | From | Fixed in |
|---|---|---|
| gstreamer_project / gstreamer | - | 1.10.2.x |