ZeroHour

CVE-2022-1925

PoC
CVSS 3.1
7.8 high
EPSS
<1%p39
Published
()
Modified
Description

DOS / potential heap overwrite in mkv demuxing using HEADERSTRIP decompression. Integer overflow in matroskaparse element in gst_matroska_decompress_data function which causes a heap overflow. Due to restrictions on chunk sizes in the matroskademux element, the overflow can't be triggered, however the matroskaparse element has no size checks.

Vendors
gstreamerdebian
Products
gstreamer, debian linux
Weakness
CWE-122, CWE-190
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.