CVE-2017-5846
Gentoo Linux Security Advisory 201705-10
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The gst_asf_demux_process_ext_stream_props function in gst/asfdemux/gstasfdemux.c in gst-plugins-ugly in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (invalid memory read and crash) via vectors related to the number of languages in a video file.
La función gst_asf_demux_process_ext_stream_props en gst/asfdemux/gstasfdemux.c en gst-plugins-ugly en GStreamer en versiones anteriores a 1.10.3 permite a atacantes remotos provocar una denegación de servicio (lectura de memoria no válida y caída) a través de vectores relacionados con el número de idiomas en un archivo de vídeo.
Hanno Boeck discovered multiple vulnerabilities in the GStreamer media framework and its codecs and demuxers, which may result in denial of service or the execution of arbitrary code if a malformed media file is opened.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-02-01 CVE Reserved
- 2017-02-09 CVE Published
- 2024-08-05 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-125: Out-of-bounds Read
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://www.openwall.com/lists/oss-security/2017/02/01/7 | Mailing List |
|
http://www.openwall.com/lists/oss-security/2017/02/02/9 | Mailing List |
|
http://www.securityfocus.com/bid/96001 | Third Party Advisory | |
https://bugzilla.gnome.org/show_bug.cgi?id=777937 | Issue Tracking | |
https://lists.debian.org/debian-lts-announce/2020/05/msg00030.html | Mailing List |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.debian.org/security/2017/dsa-3821 | 2020-05-30 | |
https://gstreamer.freedesktop.org/releases/1.10/#1.10.3 | 2020-05-30 | |
https://security.gentoo.org/glsa/201705-10 | 2020-05-30 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Gstreamer Project Search vendor "Gstreamer Project" | Gstreamer Search vendor "Gstreamer Project" for product "Gstreamer" | <= 1.10.2 Search vendor "Gstreamer Project" for product "Gstreamer" and version " <= 1.10.2" | - |
Affected
|