CVE-2017-5848: Buffer Overflow
Invalid memory read and possible buffer overflows were found in PSM parser.
Upstream bug:
https://bugzilla.gnome.org/showbug.cgi?id=777957
Upstream patch:
https://github.com/GStreamer/gst-plugins-bad/commit/948b87bf1514de
CVE assignment:
http://seclists.org/oss-sec/2017/q1/284
Other sources
The gstpsdemuxparsepsm function in gst/mpegdemux/gstmpegdemux.c in gst-plugins-bad in GStreamer allows remote attackers to cause a denial of service (invalid memory read and crash) via vectors involving PSM parsing.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5848?
The severity of CVE-2017-5848 is classified as high due to potential buffer overflows and invalid memory access.
How do I fix CVE-2017-5848?
To fix CVE-2017-5848, you should update GStreamer to version 1.11.3 or later where the vulnerability has been patched.
Which software versions are affected by CVE-2017-5848?
CVE-2017-5848 affects GStreamer versions prior to 1.11.3, Debian 8.0 and 9.0, and Red Hat Enterprise Linux versions 7.0, 7.4, 7.5, 7.6, and 7.7.
What are the risks associated with CVE-2017-5848?
The risks associated with CVE-2017-5848 include possible exploitation that may lead to remote code execution or application crashes.
Is CVE-2017-5848 being actively exploited in the wild?
As of now, there are no specific reports confirming active exploitation of CVE-2017-5848 in the wild.