The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated by thumbnailing a simple 1 frame vmnc movie that does not draw to the allocated render canvas.
https://security.gentoo.org/glsa/201705-10
https://scarybeastsecurity.blogspot.de/2016/11/0day-poc-risky-design-decisions-in.html
https://bugzilla.gnome.org/show_bug.cgi?id=774533
https://access.redhat.com/errata/RHSA-2017:2060
http://www.securityfocus.com/bid/94423