CVE-2017-5840

Priority
Low
Description
The qtdemux_parse_samples function in gst/isomp4/qtdemux.c in
gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to
cause a denial of service (out-of-bounds heap read) via vectors involving
the current stts index.
References
Bugs
Package
Upstream:needed
Ubuntu 17.10 (Artful Aardvark):DNE
Ubuntu 12.04 ESM (Precise Pangolin):DNE (precise was released [0.10.31-1ubuntu1.5])
Ubuntu 14.04 LTS (Trusty Tahr):released (0.10.31-3+nmu1ubuntu5.3)
Ubuntu Touch 15.04:ignored (reached end-of-life)
Ubuntu Core 15.04:DNE
Ubuntu 16.04 LTS (Xenial Xerus):released (0.10.31-3+nmu4ubuntu2.16.04.3)
Ubuntu 16.10 (Yakkety Yak):DNE
Ubuntu 17.04 (Zesty Zapus):DNE
Package
Upstream:released (1.10.3-1)
Ubuntu 17.10 (Artful Aardvark):not-affected (1.10.3-1ubuntu1)
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 LTS (Trusty Tahr):released (1.2.4-1~ubuntu1.4)
Ubuntu Touch 15.04:ignored (reached end-of-life)
Ubuntu Core 15.04:DNE
Ubuntu 16.04 LTS (Xenial Xerus):released (1.8.3-1ubuntu0.4)
Ubuntu 16.10 (Yakkety Yak):released (1.8.3-1ubuntu1.3)
Ubuntu 17.04 (Zesty Zapus):not-affected (1.10.3-1ubuntu1)
Patches:
Upstream:https://github.com/GStreamer/gst-plugins-good/commit/1ffef8bf6076c42bcbaaf0ec4f11ca4cf0c797da
More Information

Updated: 2017-06-15 16:18:00 UTC (commit 12747)