CVE-2017-5838: High severity Gstreamer Project Gstreamer vulnerability
An out-of-bounds read in gstdatetimenewfromiso8601string() was found that can be triggered by malformed datetime string.
Upstream bug:
https://bugzilla.gnome.org/showbug.cgi?id=777263
Upstream patch:
https://github.com/GStreamer/gstreamer/commit/9398b7f1a75b38844ae7050b5a7967e4cdebe24f
CVE assignment:
http://seclists.org/oss-sec/2017/q1/284
Other sources
The gstdatetimenewfromiso8601string function in gst/gstdatetime.c in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a malformed datetime string.
— Ubuntu
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ubuntu/gstreamer1.0to a version that resolves this vulnerability.Fixed in 1.10.3-1 - Upgrade
Upgrade
ubuntu/gstreamer1.0to a version that resolves this vulnerability.Fixed in 1.8.3-1~ubuntu0.1+ - Upgrade
Upgrade
redhat/gstreamer1to a version that resolves this vulnerability.Fixed in 1.10.3 - Upgrade
Upgrade
debian/gstreamer1.0to a version that resolves this vulnerability.Fixed in 1.14.4-1Fixed in 1.18.4-2.1Fixed in 1.22.0-2Fixed in 1.22.10-1 - Upgrade
Upgrade
GStreamerto a version that resolves this vulnerability.Fixed in 1.10.3
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5838?
CVE-2017-5838 is classified as a moderate severity vulnerability due to the potential out-of-bounds read.
How do I fix CVE-2017-5838?
To fix CVE-2017-5838, upgrade gstreamer1.0 to version 1.10.3 or higher.
What software is affected by CVE-2017-5838?
CVE-2017-5838 affects multiple versions of gstreamer1.0 on Ubuntu, Red Hat, and Debian.
What type of vulnerability is CVE-2017-5838?
CVE-2017-5838 is an out-of-bounds read vulnerability in the GStreamer library.
Can CVE-2017-5838 be triggered by user input?
Yes, CVE-2017-5838 can be triggered by a malformed datetime string provided as input.