CVE-2017-5841: High severity Gstreamer Project Gstreamer vulnerability
An out-of-bounds heap read was found gstavidemuxparsencdt.
Upstream bug:
https://bugzilla.gnome.org/showbug.cgi?id=777500
Upstream patch:
https://github.com/GStreamer/gst-plugins-good/commit/32d9f3c
CVE assignment:
http://seclists.org/oss-sec/2017/q1/284
Other sources
The gstavidemuxparsencdt function in gst/avi/gstavidemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds heap read) via vectors involving ncdt tags.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/gstreamer1-plugins-goodto a version that resolves this vulnerability.Fixed in 1.10.3 - Upgrade
Upgrade
GStreamer gst-plugins-good (gst_avi_demux_parse_ncdt / gst/avi/gstavidemux.c)to a version that resolves this vulnerability.Fixed in 1.10.3
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5841?
CVE-2017-5841 is classified as a denial of service vulnerability due to an out-of-bounds heap read.
How do I fix CVE-2017-5841?
To remediate CVE-2017-5841, update GStreamer to version 1.10.3 or later.
Which versions are affected by CVE-2017-5841?
Versions of GStreamer prior to 1.10.3, specifically up to 1.10.2, are affected by CVE-2017-5841.
What type of attack does CVE-2017-5841 enable?
CVE-2017-5841 allows remote attackers to cause a denial of service.
Where in GStreamer is CVE-2017-5841 found?
CVE-2017-5841 is found in the gst_avi_demux_parse_ncdt function within the gst/avi/gstavidemux.c file.