High severity7.5NVD Advisory· Published Feb 9, 2017· Updated May 13, 2026
CVE-2017-5843
CVE-2017-5843
Description
Multiple use-after-free vulnerabilities in the (1) gst_mini_object_unref, (2) gst_tag_list_unref, and (3) gst_mxf_demux_update_essence_tracks functions in GStreamer before 1.10.3 allow remote attackers to cause a denial of service (crash) via vectors involving stream tags, as demonstrated by 02785736.mxf.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- www.openwall.com/lists/oss-security/2017/02/02/9nvdMailing ListPatchThird Party Advisory
- www.openwall.com/lists/oss-security/2017/02/01/7nvdMailing ListThird Party Advisory
- www.securityfocus.com/bid/96001nvdThird Party AdvisoryVDB Entry
- gstreamer.freedesktop.org/releases/1.10/nvdRelease NotesVendor Advisory
- bugzilla.gnome.org/show_bug.cginvdIssue Tracking
- www.debian.org/security/2017/dsa-3818nvd
- access.redhat.com/errata/RHSA-2017:2060nvd
- lists.debian.org/debian-lts-announce/2020/03/msg00038.htmlnvd
- security.gentoo.org/glsa/201705-10nvd
News mentions
0No linked articles in our index yet.