vulnerability

SUSE: CVE-2017-5842: SUSE Linux Security Advisory

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
Published
Feb 9, 2017
Added
Mar 1, 2017
Modified
Feb 4, 2022

Description

The html_context_handle_element function in gst/subparse/samiparse.c in gst-plugins-base in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted SMI file, as demonstrated by OneNote_Manager.smi.

Solution(s)

suse-upgrade-gstreamersuse-upgrade-gstreamer-develsuse-upgrade-gstreamer-langsuse-upgrade-gstreamer-plugins-basesuse-upgrade-gstreamer-plugins-base-develsuse-upgrade-gstreamer-plugins-base-langsuse-upgrade-gstreamer-utilssuse-upgrade-libgstallocators-1_0-0suse-upgrade-libgstapp-1_0-0suse-upgrade-libgstapp-1_0-0-32bitsuse-upgrade-libgstaudio-1_0-0suse-upgrade-libgstaudio-1_0-0-32bitsuse-upgrade-libgstfft-1_0-0suse-upgrade-libgstfft-1_0-0-32bitsuse-upgrade-libgstpbutils-1_0-0suse-upgrade-libgstpbutils-1_0-0-32bitsuse-upgrade-libgstreamer-1_0-0suse-upgrade-libgstreamer-1_0-0-32bitsuse-upgrade-libgstriff-1_0-0suse-upgrade-libgstrtp-1_0-0suse-upgrade-libgstrtsp-1_0-0suse-upgrade-libgstsdp-1_0-0suse-upgrade-libgsttag-1_0-0suse-upgrade-libgsttag-1_0-0-32bitsuse-upgrade-libgstvideo-1_0-0suse-upgrade-libgstvideo-1_0-0-32bitsuse-upgrade-typelib-1_0-gst-1_0suse-upgrade-typelib-1_0-gstallocators-1_0suse-upgrade-typelib-1_0-gstapp-1_0suse-upgrade-typelib-1_0-gstaudio-1_0suse-upgrade-typelib-1_0-gstfft-1_0suse-upgrade-typelib-1_0-gstpbutils-1_0suse-upgrade-typelib-1_0-gstriff-1_0suse-upgrade-typelib-1_0-gstrtp-1_0suse-upgrade-typelib-1_0-gstrtsp-1_0suse-upgrade-typelib-1_0-gstsdp-1_0suse-upgrade-typelib-1_0-gsttag-1_0suse-upgrade-typelib-1_0-gstvideo-1_0
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.