CVE-2017-5848Out-of-bounds Read in Gstreamer

Severity
7.5HIGHNVD
EPSS
6.5%
top 8.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 9
Latest updateMay 13

Description

The gst_ps_demux_parse_psm function in gst/mpegdemux/gstmpegdemux.c in gst-plugins-bad in GStreamer allows remote attackers to cause a denial of service (invalid memory read and crash) via vectors involving PSM parsing.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

Also affects: Debian Linux 8.0, 9.0, Enterprise Linux 7.4, 7.5, 7.6, 7.7

Patches

🔴Vulnerability Details

3
GHSA
GHSA-wccf-r8h3-9jc2: The gst_ps_demux_parse_psm function in gst/mpegdemux/gstmpegdemux2022-05-13
OSV
CVE-2017-5848: The gst_ps_demux_parse_psm function in gst/mpegdemux/gstmpegdemux2017-02-09
CVEList
CVE-2017-5848: The gst_ps_demux_parse_psm function in gst/mpegdemux/gstmpegdemux2017-02-09

📋Vendor Advisories

2
Debian
CVE-2017-5848: gst-plugins-bad1.0 - The gst_ps_demux_parse_psm function in gst/mpegdemux/gstmpegdemux.c in gst-plugi...2017
Red Hat
gstreamer-plugins-bad-free: Invalid memory read in gst_ps_demux_parse_psm2016-01-30

💬Community

5
Bugzilla
CVE-2017-5843 CVE-2017-5848 mingw-gstreamer1-plugins-bad-free: various flaws [fedora-all]2017-02-06
Bugzilla
CVE-2017-5843 CVE-2017-5848 gstreamer1-plugins-bad-free: various flaws [fedora-all]2017-02-06
Bugzilla
CVE-2017-5848 gstreamer-plugins-bad-free: Invalid memory read in gst_ps_demux_parse_psm2017-02-06
Bugzilla
CVE-2017-5843 CVE-2017-5848 mingw-gstreamer-plugins-bad-free: various flaws [fedora-all]2017-02-06
Bugzilla
CVE-2017-5843 CVE-2017-5848 gstreamer-plugins-bad-free: various flaws [fedora-all]2017-02-06
CVE-2017-5848 — Out-of-bounds Read in Gstreamer | cvebase