Логотип exploitDog
bind:"GHSA-2cxw-4p8f-4qp7" OR bind:"CVE-2022-1922"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-2cxw-4p8f-4qp7" OR bind:"CVE-2022-1922"

Количество 13

Количество 13

github логотип

GHSA-2cxw-4p8f-4qp7

почти 3 года назад

DOS / potential heap overwrite in mkv demuxing using zlib decompression. Integer overflow in matroskademux element in gst_matroska_decompress_data function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities, it could be just a segfault or a heap overwrite. If the libc uses mmap for large chunks, and the OS supports mmap, then it is just a segfault (because the realloc before the integer overflow will use mremap to reduce the size of the chunk, and it will start to write to unmapped memory). However, if using a libc implementation that does not use mmap, or if the OS does not support mmap while using libc, then this could result in a heap overwrite.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2022-1922

почти 3 года назад

DOS / potential heap overwrite in mkv demuxing using zlib decompression. Integer overflow in matroskademux element in gst_matroska_decompress_data function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities, it could be just a segfault or a heap overwrite. If the libc uses mmap for large chunks, and the OS supports mmap, then it is just a segfault (because the realloc before the integer overflow will use mremap to reduce the size of the chunk, and it will start to write to unmapped memory). However, if using a libc implementation that does not use mmap, or if the OS does not support mmap while using libc, then this could result in a heap overwrite.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-1922

около 3 лет назад

DOS / potential heap overwrite in mkv demuxing using zlib decompression. Integer overflow in matroskademux element in gst_matroska_decompress_data function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities, it could be just a segfault or a heap overwrite. If the libc uses mmap for large chunks, and the OS supports mmap, then it is just a segfault (because the realloc before the integer overflow will use mremap to reduce the size of the chunk, and it will start to write to unmapped memory). However, if using a libc implementation that does not use mmap, or if the OS does not support mmap while using libc, then this could result in a heap overwrite.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2022-1922

почти 3 года назад

DOS / potential heap overwrite in mkv demuxing using zlib decompression. Integer overflow in matroskademux element in gst_matroska_decompress_data function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities, it could be just a segfault or a heap overwrite. If the libc uses mmap for large chunks, and the OS supports mmap, then it is just a segfault (because the realloc before the integer overflow will use mremap to reduce the size of the chunk, and it will start to write to unmapped memory). However, if using a libc implementation that does not use mmap, or if the OS does not support mmap while using libc, then this could result in a heap overwrite.

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2022-1922

почти 3 года назад

DOS / potential heap overwrite in mkv demuxing using zlib decompressio ...

CVSS3: 7.8
EPSS: Низкий
fstec логотип

BDU:2022-06462

почти 3 года назад

Уязвимость функции gst_matroska_decompress_data мультимедийного фреймворка Gstreamer, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 7.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3908-1

больше 2 лет назад

Security update for gstreamer-plugins-good

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3906-1

больше 2 лет назад

Security update for gstreamer-0_10-plugins-good

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:2957-1

почти 3 года назад

Security update for gstreamer-plugins-good

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:2911-1

почти 3 года назад

Security update for gstreamer-plugins-good

EPSS: Низкий
oracle-oval логотип

ELSA-2023-2260

около 2 лет назад

ELSA-2023-2260: gstreamer1-plugins-good security update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3688-1

почти 2 года назад

Security update for gstreamer-plugins-good

EPSS: Низкий
redos логотип

ROS-20240910-08

10 месяцев назад

Множественные уязвимости gstreamer1-plugins-good

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2cxw-4p8f-4qp7

DOS / potential heap overwrite in mkv demuxing using zlib decompression. Integer overflow in matroskademux element in gst_matroska_decompress_data function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities, it could be just a segfault or a heap overwrite. If the libc uses mmap for large chunks, and the OS supports mmap, then it is just a segfault (because the realloc before the integer overflow will use mremap to reduce the size of the chunk, and it will start to write to unmapped memory). However, if using a libc implementation that does not use mmap, or if the OS does not support mmap while using libc, then this could result in a heap overwrite.

CVSS3: 7.8
0%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2022-1922

DOS / potential heap overwrite in mkv demuxing using zlib decompression. Integer overflow in matroskademux element in gst_matroska_decompress_data function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities, it could be just a segfault or a heap overwrite. If the libc uses mmap for large chunks, and the OS supports mmap, then it is just a segfault (because the realloc before the integer overflow will use mremap to reduce the size of the chunk, and it will start to write to unmapped memory). However, if using a libc implementation that does not use mmap, or if the OS does not support mmap while using libc, then this could result in a heap overwrite.

CVSS3: 7.8
0%
Низкий
почти 3 года назад
redhat логотип
CVE-2022-1922

DOS / potential heap overwrite in mkv demuxing using zlib decompression. Integer overflow in matroskademux element in gst_matroska_decompress_data function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities, it could be just a segfault or a heap overwrite. If the libc uses mmap for large chunks, and the OS supports mmap, then it is just a segfault (because the realloc before the integer overflow will use mremap to reduce the size of the chunk, and it will start to write to unmapped memory). However, if using a libc implementation that does not use mmap, or if the OS does not support mmap while using libc, then this could result in a heap overwrite.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-1922

DOS / potential heap overwrite in mkv demuxing using zlib decompression. Integer overflow in matroskademux element in gst_matroska_decompress_data function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities, it could be just a segfault or a heap overwrite. If the libc uses mmap for large chunks, and the OS supports mmap, then it is just a segfault (because the realloc before the integer overflow will use mremap to reduce the size of the chunk, and it will start to write to unmapped memory). However, if using a libc implementation that does not use mmap, or if the OS does not support mmap while using libc, then this could result in a heap overwrite.

CVSS3: 7.8
0%
Низкий
почти 3 года назад
debian логотип
CVE-2022-1922

DOS / potential heap overwrite in mkv demuxing using zlib decompressio ...

CVSS3: 7.8
0%
Низкий
почти 3 года назад
fstec логотип
BDU:2022-06462

Уязвимость функции gst_matroska_decompress_data мультимедийного фреймворка Gstreamer, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 7.8
0%
Низкий
почти 3 года назад
suse-cvrf логотип
SUSE-SU-2022:3908-1

Security update for gstreamer-plugins-good

больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2022:3906-1

Security update for gstreamer-0_10-plugins-good

больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2022:2957-1

Security update for gstreamer-plugins-good

почти 3 года назад
suse-cvrf логотип
SUSE-SU-2022:2911-1

Security update for gstreamer-plugins-good

почти 3 года назад
oracle-oval логотип
ELSA-2023-2260

ELSA-2023-2260: gstreamer1-plugins-good security update (MODERATE)

около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:3688-1

Security update for gstreamer-plugins-good

почти 2 года назад
redos логотип
ROS-20240910-08

Множественные уязвимости gstreamer1-plugins-good

CVSS3: 7.8
10 месяцев назад

Уязвимостей на страницу