CVE-2017-5842 PUBLISHED

The html_context_handle_element function in gst/subparse/samiparse.c in gst-plugins-base in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted SMI file, as demonstrated by OneNote_Manager.smi.

EPSS 0.80% · 73.8th percentile

Risk Scores

EPSS Score
0.80%
73.8th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSgst-plugins-base1.01.7.2-1ubuntu1, 1.7.91-1ubuntu1, 1.8.0-1ubuntu1
Ubuntu:14.04:LTSgst-plugins-base1.00, 1.2.0-1ubuntu1, 1.2.1-2ubuntu1

Timeline

References

Open in Interactive Console →