CVE-2022-1920
Summary
| CVE | CVE-2022-1920 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-07-19 20:15:00 UTC |
| Updated | 2022-10-07 13:58:00 UTC |
| Description | Integer overflow in matroskademux element in gst_matroska_demux_add_wvpk_header function which allows a heap overwrite while parsing matroska files. Potential for arbitrary code execution through heap overwrite. |
Risk And Classification
Problem Types: CWE-787 | CWE-190
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 11.0 | All | All | All |
| Application | Gstreamer Project | Gstreamer | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] [DLA 3069-1] gst-plugins-good1.0 security update | MLIST | lists.debian.org | |
| matroska: heap overwrite in gst_matroska_demux_add_wvpk_header (#1226) · Issues · GStreamer / gstreamer · GitLab | MISC | gitlab.freedesktop.org | |
| Debian -- Security Information -- DSA-5204-1 gst-plugins-good1.0 | DEBIAN | www.debian.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160615 Oracle Enterprise Linux Security Update for gstreamer1-plugins-good (ELSA-2023-2260)
- 180925 Debian Security Update for gst-plugins-good1.0 (DLA 3069-1)
- 180926 Debian Security Update for gst-plugins-good1.0 (DSA 5204-1)
- 184155 Debian Security Update for gst-plugins-good1.0 (CVE-2022-1920)
- 198890 Ubuntu Security Notification for GStreamer Good Plugins Vulnerabilities (USN-5555-1)
- 241421 Red Hat Update for gstreamer1-plugins-good (RHSA-2023:2260)
- 296086 Oracle Solaris 11.4 Support Repository Update (SRU) 51.132.1 Missing (CPUOCT2022)
- 503597 Alpine Linux Security Update for gst-plugins-good
- 506095 Alpine Linux Security Update for gst-plugins-good
- 672070 EulerOS Security Update for gstreamer1-plugins-good (EulerOS-SA-2022-2269)
- 672187 EulerOS Security Update for gstreamer1-plugins-good (EulerOS-SA-2022-2463)
- 672236 EulerOS Security Update for gstreamer1-plugins-good (EulerOS-SA-2022-2612)
- 752512 SUSE Enterprise Linux Security Update for gstreamer-plugins-good (SUSE-SU-2022:2911-1)
- 752528 SUSE Enterprise Linux Security Update for gstreamer-plugins-good (SUSE-SU-2022:2957-1)
- 752771 SUSE Enterprise Linux Security Update for gstreamer-plugins-good (SUSE-SU-2022:3908-1)
- 754864 SUSE Enterprise Linux Security Update for gstreamer-plugins-good (SUSE-SU-2023:3688-1)
- 941005 AlmaLinux Security Update for gstreamer1-plugins-good (ALSA-2023:2260)