Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-1920

Опубликовано: 19 июл. 2022
Источник: debian
EPSS Низкий

Описание

Integer overflow in matroskademux element in gst_matroska_demux_add_wvpk_header function which allows a heap overwrite while parsing matroska files. Potential for arbitrary code execution through heap overwrite.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gst-plugins-good1.0fixed1.20.3-1package

Примечания

  • https://gstreamer.freedesktop.org/security/sa-2022-0004.html

  • https://gitlab.freedesktop.org/gstreamer/gstreamer/-/issues/1226

  • https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/cf887f1b8e228bff6e19829e6d03995d70ad739d

  • https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/0df0dd7fe388174e4835eda4526b47f470a56370 (1.20.3)

EPSS

Процентиль: 24%
0.00077
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 3 года назад

Integer overflow in matroskademux element in gst_matroska_demux_add_wvpk_header function which allows a heap overwrite while parsing matroska files. Potential for arbitrary code execution through heap overwrite.

CVSS3: 7.8
redhat
около 3 лет назад

Integer overflow in matroskademux element in gst_matroska_demux_add_wvpk_header function which allows a heap overwrite while parsing matroska files. Potential for arbitrary code execution through heap overwrite.

CVSS3: 7.8
nvd
почти 3 года назад

Integer overflow in matroskademux element in gst_matroska_demux_add_wvpk_header function which allows a heap overwrite while parsing matroska files. Potential for arbitrary code execution through heap overwrite.

CVSS3: 7.8
github
почти 3 года назад

Integer overflow in matroskademux element in gst_matroska_demux_add_wvpk_header function which allows a heap overwrite while parsing matroska files. Potential for arbitrary code execution through heap overwrite.

CVSS3: 7.8
fstec
почти 3 года назад

Уязвимость функции gst_matroska_demux_add_wvpk_header мультимедийного фреймворка Gstreamer, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 24%
0.00077
Низкий