The gstasfdemuxprocessextcontentdesc function in gst/asfdemux/gstasfdemux.c in gst-plugins-ugly in GStreamer allows remote attackers to cause a denial of service (out-of-bounds heap read) via vectors involving extended content descriptors.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*",
"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"
],
"vendor_product": "debian:debian_linux",
"source": "CPE_STRING",
"extracted_events": [
{
"last_affected": "8.0"
},
{
"last_affected": "9.0"
}
]
}
]
}[
{
"target": {
"file": "gst/asfdemux/gstasfdemux.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"279684030150557829107098172575875080776",
"19223400032722769411560383618065099160",
"294554796417022036938768244122502567476",
"264586475648032328220308509779421841923",
"130953633987926223167011240672415699377",
"14289265267665371767476224094306881851",
"340143330638629988969640357432801681471",
"76767141884024629636231774568565135171"
]
},
"deprecated": false,
"source": "https://github.com/gstreamer/gst-plugins-ugly/commit/d21017b52a585f145e8d62781bcc1c5fefc7ee37",
"signature_version": "v1",
"id": "CVE-2017-5847-23506d7f",
"signature_type": "Line"
},
{
"target": {
"function": "gst_asf_demux_process_ext_content_desc",
"file": "gst/asfdemux/gstasfdemux.c"
},
"digest": {
"function_hash": "23874994487442955161043057906492805608",
"length": 4604.0
},
"deprecated": false,
"source": "https://github.com/gstreamer/gst-plugins-ugly/commit/d21017b52a585f145e8d62781bcc1c5fefc7ee37",
"signature_version": "v1",
"id": "CVE-2017-5847-8ff06da9",
"signature_type": "Function"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-5847.json"
"2026-05-30T09:15:14Z"
{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "1.11.2"
}
],
"source": "CPE_RANGE",
"cpe": "cpe:2.3:a:gstreamer:gstreamer:*:*:*:*:*:*:*:*"
}