7.5
CVSSv3

CVE-2017-5843

Published: 09/02/2017 Updated: 05/01/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Multiple use-after-free vulnerabilities in the (1) gst_mini_object_unref, (2) gst_tag_list_unref, and (3) gst_mxf_demux_update_essence_tracks functions in GStreamer prior to 1.10.3 allow remote malicious users to cause a denial of service (crash) via vectors involving stream tags, as demonstrated by 02785736.mxf.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gstreamer project gstreamer

Vendor Advisories

Hanno Boeck discovered multiple vulnerabilities in the GStreamer media framework and its codecs and demuxers, which may result in denial of service or the execution of arbitrary code if a malformed media file is opened For the stable distribution (jessie), these problems have been fixed in version 144-21+deb8u2 For the upcoming stable distribu ...
Multiple use-after-free vulnerabilities in the (1) gst_mini_object_unref, (2) gst_tag_list_unref, and (3) gst_mxf_demux_update_essence_tracks functions in GStreamer before 1103 allow remote attackers to cause a denial of service (crash) via vectors involving stream tags, as demonstrated by 02785736mxf ...
A double-free issue has been found in gstreamer before 1103, in gst_mxf_demux_update_essence_tracks ...