Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-2122

Опубликовано: 18 мая 2022
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

DOS / potential heap overwrite in qtdemux using zlib decompression. Integer overflow in qtdemux element in qtdemux_inflate function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities, it could be just a segfault or a heap overwrite.

A flaw was found in GStreamer. An integer overflow can lead to a heap-based buffer overflow in the qt demuxer when processing a specially crafted QuickTime/MP4 file using zlib decompression. This vulnerability can result in application crash, memory corruption, and code execution.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gstreamer-plugins-goodOut of support scope
Red Hat Enterprise Linux 7gstreamer1-plugins-goodOut of support scope
Red Hat Enterprise Linux 7gstreamer-plugins-goodOut of support scope
Red Hat Enterprise Linux 8gstreamer1-plugins-goodWill not fix
Red Hat Enterprise Linux 8libreoffice:flatpak/gstreamer1-plugins-goodWill not fix
Red Hat Enterprise Linux 9libreoffice:flatpak/gstreamer1-plugins-goodAffected
Red Hat Enterprise Linux 9gstreamer1-plugins-goodFixedRHSA-2023:226009.05.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190->CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=2131018gstreamer-plugins-good: Potential heap overwrite in mp4 demuxing using zlib decompression

EPSS

Процентиль: 12%
0.00042
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 3 года назад

DOS / potential heap overwrite in qtdemux using zlib decompression. Integer overflow in qtdemux element in qtdemux_inflate function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities, it could be just a segfault or a heap overwrite.

CVSS3: 7.8
nvd
почти 3 года назад

DOS / potential heap overwrite in qtdemux using zlib decompression. Integer overflow in qtdemux element in qtdemux_inflate function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities, it could be just a segfault or a heap overwrite.

CVSS3: 7.8
debian
почти 3 года назад

DOS / potential heap overwrite in qtdemux using zlib decompression. In ...

CVSS3: 7.8
github
почти 3 года назад

DOS / potential heap overwrite in qtdemux using zlib decompression. Integer overflow in qtdemux element in qtdemux_inflate function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities, it could be just a segfault or a heap overwrite.

CVSS3: 7.8
fstec
почти 3 года назад

Уязвимость функции qtdemux_inflate мультимедийного фреймворка Gstreamer, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 12%
0.00042
Низкий

7.8 High

CVSS3