Aller au contenu

Fiche vulnérabilité

CVE-2022-1925 : faille élevée gstreamer gstreamer (CVSS 7.8)

Description

DOS / potential heap overwrite in mkv demuxing using HEADERSTRIP decompression. Integer overflow in matroskaparse element in gst_matroska_decompress_data function which causes a heap overflow. Due to restrictions on chunk sizes in the matroskademux element, the overflow can't be triggered, however the matroskaparse element has no size checks.

En bref

Sévérité
Élevée (CVSS 7.8)
Vecteur CVSS
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
19 juil. 2022
Dernière mise à jour
17 juin 2026

Produits concernés

  • gstreamer gstreamer
  • debian debian linux

Références

Rechercher une autre vulnérabilité dans la base CVE