CVE-2017-5846: Medium severity Gstreamer Project Gstreamer vulnerability
Published Feb 9, 2017
·Updated
The gstasfdemuxprocessextstreamprops function in gst/asfdemux/gstasfdemux.c in gst-plugins-ugly in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (invalid memory read and crash) via vectors related to the number of languages in a video file.
Affected Software
2 affected components
Gstreamer Project Gstreamer<=1.10.2
GStreamer GStreamer<=1.10.2
Event History
Feb 9, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-5846?
CVE-2017-5846 has a severity rating classified as high due to its potential to cause denial of service.
2
How do I fix CVE-2017-5846?
To mitigate CVE-2017-5846, update GStreamer to version 1.10.3 or later.
3
What causes the vulnerability identified by CVE-2017-5846?
CVE-2017-5846 is caused by an invalid memory read in the gst_asf_demux_process_ext_stream_props function.
4
Which versions of GStreamer are affected by CVE-2017-5846?
GStreamer versions prior to 1.10.3 are affected by CVE-2017-5846.
5
Can CVE-2017-5846 be exploited remotely?
Yes, CVE-2017-5846 can be exploited remotely, allowing attackers to crash the application.