Bugzilla – Bug 1024079
VUL-1: CVE-2017-5844: gstreamer-0_10-plugins-base,gstreamer-plugins-base: Floating point exception in gst_riff_create_audio_caps (follow-up)
Last modified: 2020-05-12 18:00:03 UTC
A crafted media file can cause a floating point exception. upstream bug: https://bugzilla.gnome.org/show_bug.cgi?id=777525 upstream commit: https://github.com/GStreamer/gst-plugins-base/commit/5d505d108800cef210f67dcfed2801ba36beac2a acknowledgments: Hanno Böck References: https://bugzilla.redhat.com/show_bug.cgi?id=1419600 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-5844 http://seclists.org/oss-sec/2017/q1/284 http://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-5844.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5844 https://bugzilla.gnome.org/show_bug.cgi?id=777955 https://bugzilla.gnome.org/show_bug.cgi?id=777957
This is a follow up to bug 1024076 in the same area. The same situation applies here, too: The upstream PoC file is in ASF format for which no support in our gstreamer codestreams is present. The fix, however, lies in gstreamer-plugins-bad and can potentielly affect other media formats using the RIFF container format, too. All codestreams of gstreamer-plugins-base and gstreamer-0_10-plugins-base contain the code in question: [affected] gstreamer-plugins-base SUSE:SLE-12-SP2:Update/gstreamer-plugins-base/gst-plugins-base-1.8.3/gst-libs/gst/riff/riff-media.c:1308 SUSE:SLE-12:Update/gstreamer-plugins-base/gst-plugins-base-1.2.4/gst-libs/gst/riff/riff-media.c:1280 gstreamer-0_10-plugins-base SUSE:SLE-12-SP2:Update/gstreamer-0_10-plugins-base/gst-plugins-base-0.10.36/gst-libs/gst/riff/riff-media.c:1199 SUSE:SLE-12:Update/gstreamer-0_10-plugins-base/gst-plugins-base-0.10.36/gst-libs/gst/riff/riff-media.c:1199 SUSE:SLE-11-SP2:Update/gstreamer-0_10-plugins-base/gst-plugins-base-0.10.35/gst-libs/gst/riff/riff-media.c:1199 SUSE:SLE-11-SP1:Update/gstreamer-0_10-plugins-base/gst-plugins-base-0.10.25/gst-libs/gst/riff/riff-media.c:1103 openSUSE:Leap:42.2:Update/gstreamer-0_10-plugins-base/gst-plugins-base-0.10.36/gst-libs/gst/riff/riff-media.c:1199
bugbot adjusting priority
This is an autogenerated message for OBS integration: This bug (1024079) was mentioned in https://build.opensuse.org/request/show/459181 42.1 / gstreamer-plugins-base
For gstreamer-plugins-base: http://build.suse.de/request/show/128291 for SLE-12-SP2 (will go automatically to 42.2) http://build.suse.de/request/show/128292 for SLE-12 http://build.opensuse.org/request/show/459181 for Leap 42.1 For gstreamer-0_10-plugins-base: http://build.suse.de/request/show/128295 for SLE-12-SP2 (will go automatically to 42.2) http://build.suse.de/request/show/128296 for SLE-12 (will go automatically to 42.1)
openSUSE-SU-2017:0574-1: An update that fixes four vulnerabilities is now available. Category: security (low) Bug References: 1024041,1024047,1024076,1024079 CVE References: CVE-2017-5837,CVE-2017-5839,CVE-2017-5842,CVE-2017-5844 Sources used: openSUSE Leap 42.1 (src): gstreamer-plugins-base-1.4.5-8.1
SUSE-SU-2017:1003-1: An update that fixes two vulnerabilities is now available. Category: security (low) Bug References: 1024076,1024079 CVE References: CVE-2017-5837,CVE-2017-5844 Sources used: SUSE Linux Enterprise Workstation Extension 12-SP2 (src): gstreamer-0_10-plugins-base-0.10.36-17.13 SUSE Linux Enterprise Software Development Kit 12-SP2 (src): gstreamer-0_10-plugins-base-0.10.36-17.13 SUSE Linux Enterprise Server 12-SP2 (src): gstreamer-0_10-plugins-base-0.10.36-17.13 SUSE Linux Enterprise Desktop 12-SP2 (src): gstreamer-0_10-plugins-base-0.10.36-17.13
SUSE-SU-2017:1012-1: An update that fixes two vulnerabilities is now available. Category: security (low) Bug References: 1024076,1024079 CVE References: CVE-2017-5837,CVE-2017-5844 Sources used: SUSE Linux Enterprise Workstation Extension 12-SP1 (src): gstreamer-0_10-plugins-base-0.10.36-11.6.9 SUSE Linux Enterprise Software Development Kit 12-SP1 (src): gstreamer-0_10-plugins-base-0.10.36-11.6.9 SUSE Linux Enterprise Server 12-SP1 (src): gstreamer-0_10-plugins-base-0.10.36-11.6.9 SUSE Linux Enterprise Desktop 12-SP1 (src): gstreamer-0_10-plugins-base-0.10.36-11.6.9
SUSE-SU-2017:1039-1: An update that fixes four vulnerabilities is now available. Category: security (low) Bug References: 1024041,1024047,1024076,1024079 CVE References: CVE-2017-5837,CVE-2017-5839,CVE-2017-5842,CVE-2017-5844 Sources used: SUSE Linux Enterprise Workstation Extension 12-SP2 (src): gstreamer-plugins-base-1.8.3-12.11 SUSE Linux Enterprise Software Development Kit 12-SP2 (src): gstreamer-plugins-base-1.8.3-12.11 SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (src): gstreamer-plugins-base-1.8.3-12.11 SUSE Linux Enterprise Server 12-SP2 (src): gstreamer-plugins-base-1.8.3-12.11 SUSE Linux Enterprise Desktop 12-SP2 (src): gstreamer-plugins-base-1.8.3-12.11
SUSE-SU-2017:1041-1: An update that fixes four vulnerabilities is now available. Category: security (low) Bug References: 1024041,1024047,1024076,1024079 CVE References: CVE-2017-5837,CVE-2017-5839,CVE-2017-5842,CVE-2017-5844 Sources used: SUSE Linux Enterprise Workstation Extension 12-SP1 (src): gstreamer-plugins-base-1.2.4-2.6.8 SUSE Linux Enterprise Software Development Kit 12-SP2 (src): gstreamer-plugins-base-1.2.4-2.6.8 SUSE Linux Enterprise Software Development Kit 12-SP1 (src): gstreamer-plugins-base-1.2.4-2.6.8 SUSE Linux Enterprise Server 12-SP1 (src): gstreamer-plugins-base-1.2.4-2.6.8 SUSE Linux Enterprise Desktop 12-SP1 (src): gstreamer-plugins-base-1.2.4-2.6.8
openSUSE-SU-2017:1079-1: An update that fixes two vulnerabilities is now available. Category: security (low) Bug References: 1024076,1024079 CVE References: CVE-2017-5837,CVE-2017-5844 Sources used: openSUSE Leap 42.1 (src): gstreamer-0_10-plugins-base-0.10.36-17.1
openSUSE-SU-2017:1106-1: An update that fixes four vulnerabilities is now available. Category: security (low) Bug References: 1024041,1024047,1024076,1024079 CVE References: CVE-2017-5837,CVE-2017-5839,CVE-2017-5842,CVE-2017-5844 Sources used: openSUSE Leap 42.2 (src): gstreamer-plugins-base-1.8.3-5.3.2
released
SUSE-SU-2019:14076-1: An update that fixes three vulnerabilities is now available. Category: security (important) Bug References: 1024076,1024079,1133375 CVE References: CVE-2017-5837,CVE-2017-5844,CVE-2019-9928 Sources used: SUSE Linux Enterprise Server 11-SP4-LTSS (src): gstreamer-0_10-plugins-base-0.10.35-5.18.5.1 SUSE Linux Enterprise Point of Sale 11-SP3 (src): gstreamer-0_10-plugins-base-0.10.35-5.18.5.1 SUSE Linux Enterprise Debuginfo 11-SP4 (src): gstreamer-0_10-plugins-base-0.10.35-5.18.5.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
all done