CVE-2017-5840: High severity Gstreamer Project Gstreamer vulnerability
An out-of-bounds heap read was found in qtdemuxparsesamples that can be triggered by specially crafted file.
Upstream bug:
https://bugzilla.gnome.org/showbug.cgi?id=777469
Upstream patches:
https://github.com/GStreamer/gst-plugins-good/commit/99d5d75 https://github.com/GStreamer/gst-plugins-good/commit/1ffef8b
CVE assignment:
http://seclists.org/oss-sec/2017/q1/284
Other sources
The qtdemuxparsesamples function in gst/isomp4/qtdemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds heap read) via vectors involving the current stts index.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/gstreamer1-plugins-goodto a version that resolves this vulnerability.Fixed in 1.10.3 - Upgrade
Upgrade
GStreamer gst-plugins-good (gst/isomp4/qtdemux.c)to a version that resolves this vulnerability.Fixed in 1.10.3 - Upgrade
Upgrade
GStreamer gst-plugins-goodto a version that resolves this vulnerability.Patch 1ffef8b - Upgrade
Upgrade
GStreamer gst-plugins-goodto a version that resolves this vulnerability.Patch 99d5d75
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5840?
CVE-2017-5840 is classified as a high severity vulnerability due to its potential to cause a denial of service.
How do I fix CVE-2017-5840?
To fix CVE-2017-5840, update GStreamer to version 1.10.3 or later.
What types of attacks can exploit CVE-2017-5840?
CVE-2017-5840 can be exploited through vectors involving the current stts index, leading to out-of-bounds heap reads.
Which versions of GStreamer are affected by CVE-2017-5840?
GStreamer versions prior to 1.10.3 are affected by CVE-2017-5840.
What components are involved in CVE-2017-5840?
CVE-2017-5840 specifically involves the qtdemux_parse_samples function in the gst-plugins-good package of GStreamer.