Описание
Integer overflow in avidemux element in gst_avi_demux_invert function which allows a heap overwrite while parsing avi files. Potential for arbitrary code execution through heap overwrite.
A flaw was found in GStreamer. An integer overflow can lead to a heap-based buffer overflow in the avi demuxer when processing a specially crafted AVI file. This vulnerability can result in application crash, memory corruption, and code execution.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 6 | gstreamer-plugins-good | Out of support scope | ||
Red Hat Enterprise Linux 7 | gstreamer1-plugins-good | Out of support scope | ||
Red Hat Enterprise Linux 7 | gstreamer-plugins-good | Out of support scope | ||
Red Hat Enterprise Linux 8 | gstreamer1-plugins-good | Will not fix | ||
Red Hat Enterprise Linux 8 | libreoffice:flatpak/gstreamer1-plugins-good | Will not fix | ||
Red Hat Enterprise Linux 9 | libreoffice:flatpak/gstreamer1-plugins-good | Affected | ||
Red Hat Enterprise Linux 9 | gstreamer1-plugins-good | Fixed | RHSA-2023:2260 | 09.05.2023 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.8 High
CVSS3
Связанные уязвимости
Integer overflow in avidemux element in gst_avi_demux_invert function which allows a heap overwrite while parsing avi files. Potential for arbitrary code execution through heap overwrite.
Integer overflow in avidemux element in gst_avi_demux_invert function which allows a heap overwrite while parsing avi files. Potential for arbitrary code execution through heap overwrite.
Integer overflow in avidemux element in gst_avi_demux_invert function ...
Integer overflow in avidemux element in gst_avi_demux_invert function which allows a heap overwrite while parsing avi files. Potential for arbitrary code execution through heap overwrite.
Уязвимость функции gst_avi_demux_invert мультимедийного фреймворка Gstreamer, позволяющая нарушителю выполнить произвольный код
EPSS
7.8 High
CVSS3