Where
AND
-Infinity
0
Severity
5.5
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

The gstasfdemuxprocessextstreamprops function in gst/asfdemux/gstasfdemux.c in gst-plugins-ugly in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (invalid memory read and crash) via vectors related to the number of languages in a video file.

First published (updated )
Severity
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An invalid memory read was found in gstavidemuxparsencdt.

Upstream bug:

https://bugzilla.gnome.org/showbug.cgi?id=777532

Upstream patch:

https://github.com/GStreamer/gst-plugins-good/commit/4f47835

CVE assignment:

http://seclists.org/oss-sec/2017/q1/284

1 / 2
Source: Red Hat
First published (updated )
Severity
7.5
Use After Free
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A use-after-free vulnerability was found in gstminiobjectunref / gsttaglistunref / gstmxfdemuxupdateessencetracks.

Upstream bug:

https://bugzilla.gnome.org/showbug.cgi?id=777503

Upstream patch:

https://github.com/GStreamer/gst-plugins-bad/commit/08723e6

CVE assignment:

http://seclists.org/oss-sec/2017/q1/284

1 / 2
Source: Red Hat
First published (updated )
Severity
5.5
Divide by Zero
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

A floating point exception was found in gstriffcreateaudiocaps.

Upstream bug:

https://bugzilla.gnome.org/showbug.cgi?id=777525

Upstream patch:

https://github.com/GStreamer/gst-plugins-base/commit/5d505d108800cef210f67dcfed2801ba36beac2a

CVE assignment:

http://seclists.org/oss-sec/2017/q1/284

1 / 2
Source: Red Hat
First published (updated )
Severity
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An out-of-bounds read in gstdatetimenewfromiso8601string() was found that can be triggered by malformed datetime string.

Upstream bug:

https://bugzilla.gnome.org/showbug.cgi?id=777263

Upstream patch:

https://github.com/GStreamer/gstreamer/commit/9398b7f1a75b38844ae7050b5a7967e4cdebe24f

CVE assignment:

http://seclists.org/oss-sec/2017/q1/284

1 / 3
Source: Red Hat
First published (updated )
Severity
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An endless recursion leading to a stack overflow in gstriffcreateaudiocaps was found.

Upstream bug:

https://bugzilla.gnome.org/showbug.cgi?id=777265

Upstream patch:

https://github.com/GStreamer/gst-plugins-base/commit/ef55c8a

CVE assignment:

http://seclists.org/oss-sec/2017/q1/284

1 / 2
Source: Red Hat
First published (updated )
Severity
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An out-of-bounds heap read was found in qtdemuxparsesamples that can be triggered by specially crafted file.

Upstream bug:

https://bugzilla.gnome.org/showbug.cgi?id=777469

Upstream patches:

https://github.com/GStreamer/gst-plugins-good/commit/99d5d75 https://github.com/GStreamer/gst-plugins-good/commit/1ffef8b

CVE assignment:

http://seclists.org/oss-sec/2017/q1/284

1 / 2
Source: Red Hat
First published (updated )
Severity
5.5
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

An out-of-bounds heap read in htmlcontexthandleelement was found.

Upstream bug:

https://bugzilla.gnome.org/showbug.cgi?id=777502

Upstream patch:

https://github.com/GStreamer/gst-plugins-base/commit/d894c19

CVE assignment:

http://seclists.org/oss-sec/2017/q1/284

1 / 2
Source: Red Hat
First published (updated )
Severity
5.5
Divide by Zero
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

A floating point exception was found in gstriffcreateaudiocaps that can be triggered by specially crafted file.

Upstream bug:

https://bugzilla.gnome.org/showbug.cgi?id=777262

Upstream patch:

https://github.com/GStreamer/gst-plugins-base/commit/81d3ba3fa212bb25fe2ac661993887c4b69af6f1

CVE assignment:

http://seclists.org/oss-sec/2017/q1/284

1 / 2
Source: Red Hat
First published (updated )
Severity
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An out-of-bounds heap read was found gstavidemuxparsencdt.

Upstream bug:

https://bugzilla.gnome.org/showbug.cgi?id=777500

Upstream patch:

https://github.com/GStreamer/gst-plugins-good/commit/32d9f3c

CVE assignment:

http://seclists.org/oss-sec/2017/q1/284

1 / 2
Source: Red Hat
First published (updated )
Severity
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An out-of-bounds read in qtdemuxtagaddstrfull was found that can be triggered by specially crafted file.

Upstream bug:

https://bugzilla.gnome.org/showbug.cgi?id=775451

Upstream patch:

https://github.com/GStreamer/gst-plugins-good/commit/d0949baf3dadea6021d54abef6802fed5a06af75

CVE assignment:

http://seclists.org/oss-sec/2017/q1/284

1 / 2
Source: Red Hat
First published (updated )
Severity
5.5
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

An invalid memory read in gstaacparsesinksetcaps was found that can be triggered by specially crafted file.

Upstream bug:

https://bugzilla.gnome.org/showbug.cgi?id=775450

Upstream patch:

https://github.com/GStreamer/gst-plugins-good/commit/87a2c140ca54c5128093377e9b25a5c24b346727

CVE assignment:

http://seclists.org/oss-sec/2017/q1/284

1 / 2
Source: Red Hat
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203