PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-5837 Gstreamer CVE debrief

CVE-2017-5837 is a denial-of-service issue in GStreamer's gst-plugins-base component. A crafted video file can trigger a floating point exception and crash in gst_riff_create_audio_caps, affecting versions before 1.10.3. The practical risk is service interruption in applications or systems that parse untrusted media with affected GStreamer builds.

Vendor
Gstreamer
Product
Unknown
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2017-02-09
Original CVE updated
2026-05-13
Advisory published
2017-02-09
Advisory updated
2026-05-13

Who should care

Security and platform teams that ship or embed GStreamer, especially maintainers of media players, transcoding services, desktop software, and Linux distributions that consume untrusted video files.

Technical summary

The vulnerable function is gst_riff_create_audio_caps in gst-libs/gst/riff/riff-media.c. According to the NVD record, the weakness is CWE-369 (divide by zero or related floating point exception class) and the impact is availability-only: a crash/DoS. The affected version range is GStreamer versions up to and including 1.10.2; the vendor release notes indicate the issue is addressed in 1.10.3.

Defensive priority

Medium. The issue is not described as code execution or data corruption, but media parsing bugs are often reachable through user-supplied files and can disrupt services or clients that process untrusted content.

Recommended defensive actions

  • Upgrade GStreamer gst-plugins-base to 1.10.3 or later, or to the first fixed version in your distribution/vendor stream.
  • Identify products that parse video files through GStreamer and confirm whether they link against affected gst-plugins-base versions.
  • Prefer distro/vendor security advisories and backports where available, such as the Debian, Red Hat, or Gentoo advisories referenced in the record.
  • Treat untrusted media as an input boundary and isolate media-processing workloads where practical.
  • Add regression tests for malformed or edge-case RIFF/video inputs in any downstream component that embeds GStreamer.

Evidence notes

Primary evidence comes from the NVD record, which states that gst_riff_create_audio_caps in gst-libs/gst/riff/riff-media.c in gst-plugins-base before 1.10.3 can be crashed by a crafted video file, causing a floating point exception and denial of service. The NVD entry maps the weakness to CWE-369 and lists affected versions through 1.10.2. The GStreamer 1.10.3 release notes are the vendor-side fix reference. The CVE record was published on 2017-02-09 and later modified on 2026-05-13; that modification date is record metadata, not the vulnerability date.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-5837 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-5837

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-5837 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5837

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.