Bug 1024079 - (CVE-2017-5844) VUL-1: CVE-2017-5844: gstreamer-0_10-plugins-base,gstreamer-plugins-base: Floating point exception in gst_riff_create_audio_caps (follow-up)
(CVE-2017-5844)
VUL-1: CVE-2017-5844: gstreamer-0_10-plugins-base,gstreamer-plugins-base: Flo...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P4 - Low : Normal
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/179857/
CVSSv2:NVD:CVE-2017-5844:4.3:(AV:N/AC...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2017-02-07 16:12 UTC by Matthias Gerstner
Modified: 2020-05-12 18:00 UTC (History)
8 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Matthias Gerstner 2017-02-07 16:14:37 UTC
This is a follow up to bug 1024076 in the same area.

The same situation applies here, too: The upstream PoC file is in ASF format
for which no support in our gstreamer codestreams is present. The fix,
however, lies in gstreamer-plugins-bad and can potentielly affect other media
formats using the RIFF container format, too.

All codestreams of gstreamer-plugins-base and gstreamer-0_10-plugins-base
contain the code in question:

[affected]

gstreamer-plugins-base

SUSE:SLE-12-SP2:Update/gstreamer-plugins-base/gst-plugins-base-1.8.3/gst-libs/gst/riff/riff-media.c:1308
SUSE:SLE-12:Update/gstreamer-plugins-base/gst-plugins-base-1.2.4/gst-libs/gst/riff/riff-media.c:1280

gstreamer-0_10-plugins-base

SUSE:SLE-12-SP2:Update/gstreamer-0_10-plugins-base/gst-plugins-base-0.10.36/gst-libs/gst/riff/riff-media.c:1199
SUSE:SLE-12:Update/gstreamer-0_10-plugins-base/gst-plugins-base-0.10.36/gst-libs/gst/riff/riff-media.c:1199
SUSE:SLE-11-SP2:Update/gstreamer-0_10-plugins-base/gst-plugins-base-0.10.35/gst-libs/gst/riff/riff-media.c:1199
SUSE:SLE-11-SP1:Update/gstreamer-0_10-plugins-base/gst-plugins-base-0.10.25/gst-libs/gst/riff/riff-media.c:1103
openSUSE:Leap:42.2:Update/gstreamer-0_10-plugins-base/gst-plugins-base-0.10.36/gst-libs/gst/riff/riff-media.c:1199
Comment 2 Swamp Workflow Management 2017-02-07 23:03:23 UTC
bugbot adjusting priority
Comment 4 Bernhard Wiedemann 2017-02-20 11:02:30 UTC
This is an autogenerated message for OBS integration:
This bug (1024079) was mentioned in
https://build.opensuse.org/request/show/459181 42.1 / gstreamer-plugins-base
Comment 5 Antonio Larrosa 2017-02-20 12:25:12 UTC
For gstreamer-plugins-base:
http://build.suse.de/request/show/128291 for SLE-12-SP2 (will go automatically to 42.2)
http://build.suse.de/request/show/128292 for SLE-12
http://build.opensuse.org/request/show/459181 for Leap 42.1

For gstreamer-0_10-plugins-base:
http://build.suse.de/request/show/128295 for SLE-12-SP2 (will go automatically to 42.2)
http://build.suse.de/request/show/128296 for SLE-12 (will go automatically to 42.1)
Comment 6 Swamp Workflow Management 2017-02-28 23:08:43 UTC
openSUSE-SU-2017:0574-1: An update that fixes four vulnerabilities is now available.

Category: security (low)
Bug References: 1024041,1024047,1024076,1024079
CVE References: CVE-2017-5837,CVE-2017-5839,CVE-2017-5842,CVE-2017-5844
Sources used:
openSUSE Leap 42.1 (src):    gstreamer-plugins-base-1.4.5-8.1
Comment 7 Swamp Workflow Management 2017-04-13 13:10:04 UTC
SUSE-SU-2017:1003-1: An update that fixes two vulnerabilities is now available.

Category: security (low)
Bug References: 1024076,1024079
CVE References: CVE-2017-5837,CVE-2017-5844
Sources used:
SUSE Linux Enterprise Workstation Extension 12-SP2 (src):    gstreamer-0_10-plugins-base-0.10.36-17.13
SUSE Linux Enterprise Software Development Kit 12-SP2 (src):    gstreamer-0_10-plugins-base-0.10.36-17.13
SUSE Linux Enterprise Server 12-SP2 (src):    gstreamer-0_10-plugins-base-0.10.36-17.13
SUSE Linux Enterprise Desktop 12-SP2 (src):    gstreamer-0_10-plugins-base-0.10.36-17.13
Comment 8 Swamp Workflow Management 2017-04-13 13:15:26 UTC
SUSE-SU-2017:1012-1: An update that fixes two vulnerabilities is now available.

Category: security (low)
Bug References: 1024076,1024079
CVE References: CVE-2017-5837,CVE-2017-5844
Sources used:
SUSE Linux Enterprise Workstation Extension 12-SP1 (src):    gstreamer-0_10-plugins-base-0.10.36-11.6.9
SUSE Linux Enterprise Software Development Kit 12-SP1 (src):    gstreamer-0_10-plugins-base-0.10.36-11.6.9
SUSE Linux Enterprise Server 12-SP1 (src):    gstreamer-0_10-plugins-base-0.10.36-11.6.9
SUSE Linux Enterprise Desktop 12-SP1 (src):    gstreamer-0_10-plugins-base-0.10.36-11.6.9
Comment 9 Swamp Workflow Management 2017-04-18 13:09:24 UTC
SUSE-SU-2017:1039-1: An update that fixes four vulnerabilities is now available.

Category: security (low)
Bug References: 1024041,1024047,1024076,1024079
CVE References: CVE-2017-5837,CVE-2017-5839,CVE-2017-5842,CVE-2017-5844
Sources used:
SUSE Linux Enterprise Workstation Extension 12-SP2 (src):    gstreamer-plugins-base-1.8.3-12.11
SUSE Linux Enterprise Software Development Kit 12-SP2 (src):    gstreamer-plugins-base-1.8.3-12.11
SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (src):    gstreamer-plugins-base-1.8.3-12.11
SUSE Linux Enterprise Server 12-SP2 (src):    gstreamer-plugins-base-1.8.3-12.11
SUSE Linux Enterprise Desktop 12-SP2 (src):    gstreamer-plugins-base-1.8.3-12.11
Comment 10 Swamp Workflow Management 2017-04-18 13:11:19 UTC
SUSE-SU-2017:1041-1: An update that fixes four vulnerabilities is now available.

Category: security (low)
Bug References: 1024041,1024047,1024076,1024079
CVE References: CVE-2017-5837,CVE-2017-5839,CVE-2017-5842,CVE-2017-5844
Sources used:
SUSE Linux Enterprise Workstation Extension 12-SP1 (src):    gstreamer-plugins-base-1.2.4-2.6.8
SUSE Linux Enterprise Software Development Kit 12-SP2 (src):    gstreamer-plugins-base-1.2.4-2.6.8
SUSE Linux Enterprise Software Development Kit 12-SP1 (src):    gstreamer-plugins-base-1.2.4-2.6.8
SUSE Linux Enterprise Server 12-SP1 (src):    gstreamer-plugins-base-1.2.4-2.6.8
SUSE Linux Enterprise Desktop 12-SP1 (src):    gstreamer-plugins-base-1.2.4-2.6.8
Comment 11 Swamp Workflow Management 2017-04-20 16:09:40 UTC
openSUSE-SU-2017:1079-1: An update that fixes two vulnerabilities is now available.

Category: security (low)
Bug References: 1024076,1024079
CVE References: CVE-2017-5837,CVE-2017-5844
Sources used:
openSUSE Leap 42.1 (src):    gstreamer-0_10-plugins-base-0.10.36-17.1
Comment 12 Swamp Workflow Management 2017-04-26 16:10:58 UTC
openSUSE-SU-2017:1106-1: An update that fixes four vulnerabilities is now available.

Category: security (low)
Bug References: 1024041,1024047,1024076,1024079
CVE References: CVE-2017-5837,CVE-2017-5839,CVE-2017-5842,CVE-2017-5844
Sources used:
openSUSE Leap 42.2 (src):    gstreamer-plugins-base-1.8.3-5.3.2
Comment 13 Marcus Meissner 2018-09-10 13:40:24 UTC
released
Comment 16 Swamp Workflow Management 2019-06-11 13:12:08 UTC
SUSE-SU-2019:14076-1: An update that fixes three vulnerabilities is now available.

Category: security (important)
Bug References: 1024076,1024079,1133375
CVE References: CVE-2017-5837,CVE-2017-5844,CVE-2019-9928
Sources used:
SUSE Linux Enterprise Server 11-SP4-LTSS (src):    gstreamer-0_10-plugins-base-0.10.35-5.18.5.1
SUSE Linux Enterprise Point of Sale 11-SP3 (src):    gstreamer-0_10-plugins-base-0.10.35-5.18.5.1
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    gstreamer-0_10-plugins-base-0.10.35-5.18.5.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 17 Alexandros Toptsoglou 2019-12-13 15:21:27 UTC
all done