CVE-2017-5844: Divide by Zero
A floating point exception was found in gstriffcreateaudiocaps.
Upstream bug:
https://bugzilla.gnome.org/showbug.cgi?id=777525
Upstream patch:
https://github.com/GStreamer/gst-plugins-base/commit/5d505d108800cef210f67dcfed2801ba36beac2a
CVE assignment:
http://seclists.org/oss-sec/2017/q1/284
Other sources
The gstriffcreateaudiocaps function in gst-libs/gst/riff/riff-media.c in gst-plugins-base in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (floating point exception and crash) via a crafted ASF file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/gstreamer1-plugins-baseto a version that resolves this vulnerability.Fixed in 1.10.3 - Upgrade
Upgrade
GStreamer gst-plugins-base (gst-libs/gst/riff/riff-media.c)to a version that resolves this vulnerability.Fixed in 1.10.3 - Compensating control
Apply the upstream fix commit for the vulnerability in GStreamer gst-plugins-base (gst_riff_create_audio_caps) referenced as commit 5d505d108800cef210f67dcfed2801ba36beac2a, since it addresses the denial-of-service via crafted ASF files.
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5844?
CVE-2017-5844 has a high severity level due to a floating point exception which can lead to application crashes.
How do I fix CVE-2017-5844?
To fix CVE-2017-5844, update GStreamer to version 1.10.3 or later.
What software is affected by CVE-2017-5844?
CVE-2017-5844 affects GStreamer versions up to 1.10.2.
Are there any known exploits for CVE-2017-5844?
As of now, there are no reported active exploits for CVE-2017-5844 in the wild.
What kind of applications might be impacted by CVE-2017-5844?
Applications using the GStreamer audio processing library are likely to be impacted by CVE-2017-5844.