GCVE-VVD-MAGEIA-2017-348
Advisory Published
Vulnetix · Advisory published September 21, 2017
A crafted AAC audio file could have caused an invalid read and thus corruption or denial of service (CVE-2016-10198). A crafted mp4 file could have caused an invalid read and thus corruption or denial of service (CVE-2016-10199). A crafted AVI file could have caused an invalid read and thus corruption or denial of service (CVE-2017-5840). A crafted AVI file with metadata tag entries (ncdt) could have caused invalid read access and thus corruption or denial of service (CVE-2017-5841). A crafted AVI file could have caused an invalid read access resulting in denial of service (CVE-2017-5845). Note that GStreamer 0.10 was only affected by CVE-2016-10198 and CVE-2017-5840.

Affected Products

VendorProductVersionsPlatforms
Mageiagstreamer1.0-plugins-good0 (affected), 1.4.3-2.2.mga5 (unaffected)
Mageiagstreamer0.10-plugins-good0 (affected), 0.10.31-9.2.mga5 (unaffected)

Aliases

Transitive aliases

References

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.