CVE-2017-5847 PUBLISHED

The gst_asf_demux_process_ext_content_desc function in gst/asfdemux/gstasfdemux.c in gst-plugins-ugly in GStreamer allows remote attackers to cause a denial of service (out-of-bounds heap read) via vectors involving extended content descriptors.

EPSS 3.07% · 86.7th percentile

Risk Scores

EPSS Score
3.07%
86.7th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSgst-plugins-ugly1.01.8.1-1ubuntu0.1, 1.7.2-1ubuntu1, 1.7.91-1ubuntu1
Ubuntu:14.04:LTSgst-plugins-ugly0.100.10.19-2, 0.10.19-2ubuntu1, 0.10.19-2ubuntu2

Timeline

References

Open in Interactive Console →