PatchSiren cyber security CVE debrief
CVE-2017-5845 Gstreamer CVE debrief
CVE-2017-5845 is a high-severity denial-of-service issue in GStreamer's AVI demuxer. A malformed ncdt sub-tag in an AVI file can make gst_avi_demux_parse_ncdt read invalid memory and crash the process. GStreamer fixed the issue in 1.10.3; NVD lists affected gst-plugins-good versions through 1.10.2.
- Vendor
- Gstreamer
- Product
- Unknown
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-09
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-09
- Advisory updated
- 2026-05-13
Who should care
Teams that ship or embed GStreamer gst-plugins-good, especially software that processes untrusted AVI media. This includes desktop media apps, transcoding pipelines, preview/indexing services, and any product that parses user-supplied files.
Technical summary
The vulnerable function is gst_avi_demux_parse_ncdt in gst/avi/gstavidemux.c. According to NVD, a remote attacker can trigger an invalid memory read and crash by supplying an ncdt sub-tag that goes behind the surrounding tag. NVD maps the issue to CWE-125 and marks the attack vector as network-based with no privileges or user interaction required. Affected versions are listed as GStreamer up to and including 1.10.2; the fix is referenced in the GStreamer 1.10.3 release notes.
Defensive priority
High for environments that accept or process untrusted media files. The issue is remotely triggerable and can reliably terminate the parsing process, which is operationally significant even though the impact is availability only.
Recommended defensive actions
- Upgrade GStreamer / gst-plugins-good to 1.10.3 or later.
- Inventory products that bundle or statically ship gst-plugins-good and confirm they include the fixed release.
- Treat untrusted AVI files as attack surface and route them through patched parsers only.
- Add crash monitoring and fuzzing coverage for AVI demuxing paths if you maintain downstream media code.
- Use vendor and distro advisories referenced by the CVE to verify backported fixes in packaged builds.
Evidence notes
Grounded in the NVD CVE record and the referenced GStreamer release notes. NVD describes the flaw as an invalid memory read leading to crash in gst_avi_demux_parse_ncdt, assigns CWE-125, and lists vulnerable versions through 1.10.2. The GStreamer 1.10.3 release notes are cited as the vendor fix reference. Public references in the CVE metadata include an issue tracker entry (GNOME Bug 777532), mailing list discussion, and distro advisories. CVE published date used here is 2017-02-09; modified date is 2026-05-13.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-5845 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-5845
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-5845 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5845
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2017:2060
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://gstreamer.freedesktop.org/releases/1.10/
[email protected] - Release Notes, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.