~ubuntu-security/ubuntu-cve-tracker/master

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
PublicDateAtUSN: 2017-02-09
Candidate: CVE-2017-5839
PublicDate: 2017-02-09
References:
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5839
 http://www.openwall.com/lists/oss-security/2017/02/01/7
 http://www.ubuntu.com/usn/usn-3244-1
Description:
 The gst_riff_create_audio_caps function in gst-libs/gst/riff/riff-media.c
 in gst-plugins-base in GStreamer before 1.10.3 does not properly limit
 recursion, which allows remote attackers to cause a denial of service
 (stack overflow and crash) via vectors involving nested WAVEFORMATEX.
Ubuntu-Description:
Notes:
Bugs:
 https://bugzilla.gnome.org/show_bug.cgi?id=777265
Priority: low
Discovered-by: Hanno Böck
Assigned-to:

Patches_gst-plugins-base0.10:
upstream_gst-plugins-base0.10: needed
precise_gst-plugins-base0.10: not-affected (code not present)
precise/esm_gst-plugins-base0.10: DNE (precise was not-affected [code not present])
trusty_gst-plugins-base0.10: not-affected (code not present)
vivid/stable-phone-overlay_gst-plugins-base0.10: not-affected (code not present)
vivid/ubuntu-core_gst-plugins-base0.10: DNE
xenial_gst-plugins-base0.10: not-affected (code not present)
yakkety_gst-plugins-base0.10: DNE
zesty_gst-plugins-base0.10: DNE
devel_gst-plugins-base0.10: DNE

Patches_gst-plugins-base1.0:
 upstream: https://github.com/GStreamer/gst-plugins-base/commit/ef55c8a6b7ca746b2d1b55129a404eb5f58cf140
upstream_gst-plugins-base1.0: released (1.10.3-1)
precise_gst-plugins-base1.0: DNE
precise/esm_gst-plugins-base1.0: DNE
trusty_gst-plugins-base1.0: released (1.2.4-1~ubuntu2.1)
vivid/stable-phone-overlay_gst-plugins-base1.0: ignored (reached end-of-life)
vivid/ubuntu-core_gst-plugins-base1.0: DNE
xenial_gst-plugins-base1.0: released (1.8.3-1ubuntu0.2)
yakkety_gst-plugins-base1.0: released (1.8.3-1ubuntu1.1)
zesty_gst-plugins-base1.0: not-affected (1.10.3-1ubuntu1)
devel_gst-plugins-base1.0: not-affected (1.10.3-1ubuntu1)