The gstasfdemuxprocessextcontentdesc function in gst/asfdemux/gstasfdemux.c in gst-plugins-ugly in GStreamer allows remote attackers to cause a denial of service (out-of-bounds heap read) via vectors involving extended content descriptors.
{ "vanir_signatures": [ { "id": "CVE-2017-5847-23506d7f", "digest": { "line_hashes": [ "279684030150557829107098172575875080776", "19223400032722769411560383618065099160", "294554796417022036938768244122502567476", "264586475648032328220308509779421841923", "130953633987926223167011240672415699377", "14289265267665371767476224094306881851", "340143330638629988969640357432801681471", "76767141884024629636231774568565135171" ], "threshold": 0.9 }, "signature_type": "Line", "deprecated": false, "target": { "file": "gst/asfdemux/gstasfdemux.c" }, "signature_version": "v1", "source": "https://github.com/gstreamer/gst-plugins-ugly/commit/d21017b52a585f145e8d62781bcc1c5fefc7ee37" }, { "id": "CVE-2017-5847-8ff06da9", "digest": { "length": 4604.0, "function_hash": "23874994487442955161043057906492805608" }, "signature_type": "Function", "deprecated": false, "target": { "file": "gst/asfdemux/gstasfdemux.c", "function": "gst_asf_demux_process_ext_content_desc" }, "signature_version": "v1", "source": "https://github.com/gstreamer/gst-plugins-ugly/commit/d21017b52a585f145e8d62781bcc1c5fefc7ee37" } ] }