CVE-2017-5845
09.02.2017, 15:59
The gst_avi_demux_parse_ncdt function in gst/avi/gstavidemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (invalid memory read and crash) via a ncdt sub-tag that "goes behind" the surrounding tag.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| gstreamer | gstreamer | 𝑥 ≤ 1.10.2 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| gstreamer |
| ||||||||||||||||||||||||||||||||||||||||||||||||
| gstreamer-devel |
| ||||||||||||||||||||||||||||||||||||||||||||||||
| gstreamer-lang |
| ||||||||||||||||||||||||||||||||||||||||||||||||
| gstreamer-plugins-good |
| ||||||||||||||||||||||||||||||||||||||||||||||||
| gstreamer-plugins-good-lang |
| ||||||||||||||||||||||||||||||||||||||||||||||||
| gstreamer-utils |
| ||||||||||||||||||||||||||||||||||||||||||||||||
| libgstreamer-1_0-0 |
| ||||||||||||||||||||||||||||||||||||||||||||||||
| typelib-1_0-Gst-1_0 |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||
|---|---|---|---|
| clutter-gst2 |
| ||
| clutter-gst2-devel |
| ||
| gnome-video-effects |
| ||
| gstreamer-plugins-bad-free |
| ||
| gstreamer-plugins-bad-free-devel |
| ||
| gstreamer-plugins-bad-free-devel-docs |
| ||
| gstreamer-plugins-good |
| ||
| gstreamer-plugins-good-devel-docs |
| ||
| gstreamer1 |
| ||
| gstreamer1-devel |
| ||
| gstreamer1-devel-docs |
| ||
| gstreamer1-plugins-bad-free |
| ||
| gstreamer1-plugins-bad-free-devel |
| ||
| gstreamer1-plugins-bad-free-gtk |
| ||
| gstreamer1-plugins-base |
| ||
| gstreamer1-plugins-base-devel |
| ||
| gstreamer1-plugins-base-devel-docs |
| ||
| gstreamer1-plugins-base-tools |
| ||
| gstreamer1-plugins-good |
| ||
| orc |
| ||
| orc-compiler |
| ||
| orc-devel |
| ||
| orc-doc |
|
Common Weakness Enumeration
References