Denial of Service Vulnerability in GStreamer by GStreamer Project
CVE-2017-5837

5.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
9 February 2017

What is CVE-2017-5837?

The gst_riff_create_audio_caps function in the GStreamer library (specifically in gst-plugins-base) prior to version 1.10.3 is susceptible to a denial of service attack. Remote attackers can exploit this vulnerability by crafting a malicious video file that triggers a floating point exception and subsequently causes the application to crash. This vulnerability highlights the importance of validating inputs and ensuring robust error handling to protect against unexpected scenarios.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.