PatchSiren cyber security CVE debrief
CVE-2017-5847 Debian CVE debrief
CVE-2017-5847 is a remotely triggerable denial-of-service issue in GStreamer's ASF demuxer code. The vulnerable function, gst_asf_demux_process_ext_content_desc in gst/asfdemux/gstasfdemux.c, can read past the bounds of heap memory while processing extended content descriptors. NVD rates the issue as high availability impact with network access and no authentication or user interaction required (CVSS 3.1: 7.5, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). The NVD record lists affected GStreamer versions before 1.11.2 and also maps Debian 8.0 and 9.0 as vulnerable platforms.
- Vendor
- Debian
- Product
- Unknown
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-09
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-09
- Advisory updated
- 2026-05-13
Who should care
Administrators and developers who run or ship GStreamer-based media parsers, especially software that ingests untrusted ASF content or packages gst-plugins-ugly on Debian 8/9 or similarly aged builds.
Technical summary
The weakness is a CWE-125 out-of-bounds read in ASF extended content descriptor parsing. Because the parsing path is reachable from remote media input and requires no privileges or user interaction, malformed input can disrupt the consuming process or service. The supplied NVD vector identifies the impact as availability-only, with no confidentiality or integrity impact recorded.
Defensive priority
High priority: fix or remove vulnerable GStreamer gst-plugins-ugly builds in any service that processes untrusted media input.
Recommended defensive actions
- Upgrade GStreamer / gst-plugins-ugly to a version that includes the fix; the NVD criteria mark versions before 1.11.2 as vulnerable.
- If you rely on Debian packages, apply the relevant Debian security update referenced by DSA-3821 and confirm the installed package build is patched.
- Inventory applications and services that use GStreamer to parse ASF media, and prioritize them if they are exposed to remote or user-supplied content.
- Reduce exposure by isolating media parsing components and rejecting or sandboxing untrusted ASF files until patched versions are deployed.
Evidence notes
The supplied NVD record identifies the issue as CWE-125 and gives CVSS 3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. It also lists vulnerable GStreamer criteria ending before 1.11.2 and Debian 8.0/9.0 CPEs. NVD references include a Debian advisory (ref-4), upstream mailing-list posts (ref-5, ref-6), a GNOME issue tracker entry (ref-8), and the GStreamer patch commit (ref-9), which together corroborate the component, fix trail, and distro remediation context.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-5847 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-5847
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-5847 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5847
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/GStreamer/gst-plugins-ugly/commit/d21017b52a585f145e8d62781bcc1c5fefc7ee37
[email protected] - Patch, Third Party Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://lists.debian.org/debian-lts-announce/2020/05/msg00030.html
[email protected] - Mailing List, Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.