CVE-2017-5847: High severity Gstreamer Project Gstreamer vulnerability
The gstasfdemuxprocessextcontentdesc function in gst/asfdemux/gstasfdemux.c in gst-plugins-ugly in GStreamer allows remote attackers to cause a denial of service (out-of-bounds heap read) via vectors involving extended content descriptors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5847?
CVE-2017-5847 is classified as a medium severity vulnerability due to its potential for denial of service.
How do I fix CVE-2017-5847?
To fix CVE-2017-5847, update GStreamer to the latest version that is higher than 1.11.2.
What platforms are affected by CVE-2017-5847?
CVE-2017-5847 affects GStreamer versions prior to 1.11.2, as well as Debian Linux versions 8.0 and 9.0.
How does CVE-2017-5847 exploit occur?
CVE-2017-5847 can be exploited through a denial of service caused by an out-of-bounds heap read in the gst_asf_demux_process_ext_content_desc function.
Who can be targeted by CVE-2017-5847?
CVE-2017-5847 can target users of vulnerable GStreamer implementations and Debian installations.