CVE-2022-1924
Summary
| CVE | CVE-2022-1924 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-07-19 20:15:00 UTC |
| Updated | 2023-06-27 15:51:00 UTC |
| Description | DOS / potential heap overwrite in mkv demuxing using lzo decompression. Integer overflow in matroskademux element in lzo decompression function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities, it could be just a segfault or a heap overwrite. If the libc uses mmap for large chunks, and the OS supports mmap, then it is just a segfault (because the realloc before the integer overflow will use mremap to reduce the size of the chunk, and it will start to write to unmapped memory). However, if using a libc implementation that does not use mmap, or if the OS does not support mmap while using libc, then this could result in a heap overwrite. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| matroska: segfault / potential heap overflow in zlib decoding (#1225) · Issues · GStreamer / gstreamer · GitLab |
MISC |
gitlab.freedesktop.org |
|
| [SECURITY] [DLA 3069-1] gst-plugins-good1.0 security update |
MLIST |
lists.debian.org |
|
| Debian -- Security Information -- DSA-5204-1 gst-plugins-good1.0 |
DEBIAN |
www.debian.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160615 Oracle Enterprise Linux Security Update for gstreamer1-plugins-good (ELSA-2023-2260)
- 180925 Debian Security Update for gst-plugins-good1.0 (DLA 3069-1)
- 180926 Debian Security Update for gst-plugins-good1.0 (DSA 5204-1)
- 183052 Debian Security Update for gst-plugins-good1.0 (CVE-2022-1924)
- 198890 Ubuntu Security Notification for GStreamer Good Plugins Vulnerabilities (USN-5555-1)
- 241421 Red Hat Update for gstreamer1-plugins-good (RHSA-2023:2260)
- 503597 Alpine Linux Security Update for gst-plugins-good
- 506095 Alpine Linux Security Update for gst-plugins-good
- 672070 EulerOS Security Update for gstreamer1-plugins-good (EulerOS-SA-2022-2269)
- 672187 EulerOS Security Update for gstreamer1-plugins-good (EulerOS-SA-2022-2463)
- 672236 EulerOS Security Update for gstreamer1-plugins-good (EulerOS-SA-2022-2612)
- 752512 SUSE Enterprise Linux Security Update for gstreamer-plugins-good (SUSE-SU-2022:2911-1)
- 752528 SUSE Enterprise Linux Security Update for gstreamer-plugins-good (SUSE-SU-2022:2957-1)
- 752771 SUSE Enterprise Linux Security Update for gstreamer-plugins-good (SUSE-SU-2022:3908-1)
- 754864 SUSE Enterprise Linux Security Update for gstreamer-plugins-good (SUSE-SU-2023:3688-1)
- 941005 AlmaLinux Security Update for gstreamer1-plugins-good (ALSA-2023:2260)