CVE-2017-5838 PUBLISHED

The gst_date_time_new_from_iso8601_string function in gst/gstdatetime.c in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a malformed datetime string.

EPSS 2.76% · 85.9th percentile

Risk Scores

EPSS Score
2.76%
85.9th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSgstreamer1.00, 1.6.0-1, 1.6.1-1
Ubuntu:16.04:LTSgstreamer0.100, 0.10.36-1.5ubuntu1

Timeline

References

Open in Interactive Console →