CVE-2017-5837: Divide by Zero
A floating point exception was found in gstriffcreateaudiocaps that can be triggered by specially crafted file.
Upstream bug:
https://bugzilla.gnome.org/showbug.cgi?id=777262
Upstream patch:
https://github.com/GStreamer/gst-plugins-base/commit/81d3ba3fa212bb25fe2ac661993887c4b69af6f1
CVE assignment:
http://seclists.org/oss-sec/2017/q1/284
Other sources
The gstriffcreateaudiocaps function in gst-libs/gst/riff/riff-media.c in gst-plugins-base in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (floating point exception and crash) via a crafted video file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/gstreamer1-plugins-baseto a version that resolves this vulnerability.Fixed in 1.10.3 - Upgrade
Upgrade
GStreamer gst-plugins-base (gst-libs/gst/riff/riff-media.c)to a version that resolves this vulnerability.Fixed in 1.10.3
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5837?
CVE-2017-5837 has been classified as a high severity vulnerability that can lead to denial of service.
How do I fix CVE-2017-5837?
To fix CVE-2017-5837, update the GStreamer package to version 1.10.3 or later.
What type of attack is associated with CVE-2017-5837?
CVE-2017-5837 allows remote attackers to exploit a crafted video file to cause a denial of service.
Which GStreamer versions are affected by CVE-2017-5837?
GStreamer versions up to and including 1.10.2 are affected by CVE-2017-5837.
What component of GStreamer does CVE-2017-5837 impact?
CVE-2017-5837 impacts the gst_riff_create_audio_caps function in the gst-plugins-base component.