The flx_decode_chunks function in gst/flx/gstflxdec.c in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted FLIC file. http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-9807