PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-5841 Gstreamer CVE debrief

CVE-2017-5841 is a remotely triggerable denial-of-service issue in GStreamer’s AVI demuxer. Crafted AVI content with ncdt tags can reach an out-of-bounds heap read in gst_avi_demux_parse_ncdt, affecting gst-plugins-good before 1.10.3 and versions through 1.10.2 per the supplied NVD data.

Vendor
Gstreamer
Product
Unknown
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2017-02-09
Original CVE updated
2026-05-13
Advisory published
2017-02-09
Advisory updated
2026-05-13

Who should care

Teams that deploy or embed GStreamer gst-plugins-good to process untrusted media should care most, especially services that accept AVI files from users, ingest pipelines, preview/thumbnail systems, and desktop applications that may open attacker-supplied media.

Technical summary

The supplied corpus identifies an out-of-bounds heap read in gst_avi_demux_parse_ncdt within gst/avi/gstavidemux.c. NVD classifies the weakness as CWE-125 and lists the affected range as GStreamer 1.10.2 and earlier, with the fix landing in 1.10.3. The CVSS vector indicates network attack, no privileges, no user interaction, and availability impact only (CVSS 7.5, HIGH).

Defensive priority

High for any system that parses untrusted AVI media; prioritize patching exposed or large-scale media processing environments first.

Recommended defensive actions

  • Upgrade GStreamer gst-plugins-good to 1.10.3 or later, or install the vendor/backport fix provided by your distribution.
  • Confirm deployed package versions against the affected range listed by NVD (through 1.10.2).
  • Reduce exposure to untrusted AVI inputs where practical, especially in automated processing or internet-facing services.
  • Watch for crashes or abnormal termination in media ingestion, transcoding, or preview workflows that consume AVI files.
  • Track downstream advisories and errata for your platform, including vendor release notes and distribution security notices.

Evidence notes

All claims are limited to the supplied corpus. The vulnerability description states a remote denial of service via an out-of-bounds heap read in gst_avi_demux_parse_ncdt involving ncdt tags. NVD’s CPE criteria list GStreamer versions up to 1.10.2 as vulnerable, and the referenced GStreamer release notes point to 1.10.3 as the fix.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-5841 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-5841

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-5841 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5841

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.