CVE-2017-5839 PUBLISHED

The gst_riff_create_audio_caps function in gst-libs/gst/riff/riff-media.c in gst-plugins-base in GStreamer before 1.10.3 does not properly limit recursion, which allows remote attackers to cause a denial of service (stack overflow and crash) via vectors involving nested WAVEFORMATEX.

EPSS 3.04% · 86.6th percentile

Risk Scores

EPSS Score
3.04%
86.6th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSgst-plugins-base1.01.2.0-1ubuntu1, 1.2.1-2ubuntu1, 1.2.1-2ubuntu2
Ubuntu:16.04:LTSgst-plugins-base1.01.6.0-1ubuntu1, 1.6.1-1ubuntu1, 1.7.1-1ubuntu1

Timeline

References

Open in Interactive Console →