Описание
Security update for gstreamer-plugins-base
This update for gstreamer-plugins-base fixes the following security issues:
- A crafted AVI file could have caused a floating point exception leading to DoS (bsc#1024076, CVE-2017-5837, bsc#1024079, CVE-2017-5844)
- A crafted AVI file could have caused a stack overflow leading to DoS (bsc#1024047, CVE-2017-5839)
- A crafted SAMI subtitle file could have caused an invalid memory access possibly leading to DoS or corruption (bsc#1024041, CVE-2017-5842)
Список пакетов
openSUSE Leap 42.1
Ссылки
- E-Mail link for openSUSE-SU-2017:0574-1
- SUSE Security Ratings
Описание
The gst_riff_create_audio_caps function in gst-libs/gst/riff/riff-media.c in gst-plugins-base in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (floating point exception and crash) via a crafted video file.
Затронутые продукты
Ссылки
- CVE-2017-5837
- SUSE Bug 1023259
- SUSE Bug 1024076
- SUSE Bug 1024079
Описание
The gst_riff_create_audio_caps function in gst-libs/gst/riff/riff-media.c in gst-plugins-base in GStreamer before 1.10.3 does not properly limit recursion, which allows remote attackers to cause a denial of service (stack overflow and crash) via vectors involving nested WAVEFORMATEX.
Затронутые продукты
Ссылки
- CVE-2017-5839
- SUSE Bug 1023259
- SUSE Bug 1024047
Описание
The html_context_handle_element function in gst/subparse/samiparse.c in gst-plugins-base in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted SMI file, as demonstrated by OneNote_Manager.smi.
Затронутые продукты
Ссылки
- CVE-2017-5842
- SUSE Bug 1023259
- SUSE Bug 1024041
Описание
The gst_riff_create_audio_caps function in gst-libs/gst/riff/riff-media.c in gst-plugins-base in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (floating point exception and crash) via a crafted ASF file.
Затронутые продукты
Ссылки
- CVE-2017-5844
- SUSE Bug 1023259
- SUSE Bug 1024079