CVE-2022-1925
Summary
| CVE | CVE-2022-1925 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-07-19 20:15:00 UTC |
| Updated | 2023-06-27 15:50:00 UTC |
| Description | DOS / potential heap overwrite in mkv demuxing using HEADERSTRIP decompression. Integer overflow in matroskaparse element in gst_matroska_decompress_data function which causes a heap overflow. Due to restrictions on chunk sizes in the matroskademux element, the overflow can't be triggered, however the matroskaparse element has no size checks. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| matroska: segfault / potential heap overflow in zlib decoding (#1225) · Issues · GStreamer / gstreamer · GitLab |
MISC |
gitlab.freedesktop.org |
|
| [SECURITY] [DLA 3069-1] gst-plugins-good1.0 security update |
MLIST |
lists.debian.org |
|
| Debian -- Security Information -- DSA-5204-1 gst-plugins-good1.0 |
DEBIAN |
www.debian.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160615 Oracle Enterprise Linux Security Update for gstreamer1-plugins-good (ELSA-2023-2260)
- 180925 Debian Security Update for gst-plugins-good1.0 (DLA 3069-1)
- 180926 Debian Security Update for gst-plugins-good1.0 (DSA 5204-1)
- 184135 Debian Security Update for gst-plugins-good1.0 (CVE-2022-1925)
- 198890 Ubuntu Security Notification for GStreamer Good Plugins Vulnerabilities (USN-5555-1)
- 241421 Red Hat Update for gstreamer1-plugins-good (RHSA-2023:2260)
- 503597 Alpine Linux Security Update for gst-plugins-good
- 506095 Alpine Linux Security Update for gst-plugins-good
- 672070 EulerOS Security Update for gstreamer1-plugins-good (EulerOS-SA-2022-2269)
- 672187 EulerOS Security Update for gstreamer1-plugins-good (EulerOS-SA-2022-2463)
- 672236 EulerOS Security Update for gstreamer1-plugins-good (EulerOS-SA-2022-2612)
- 752512 SUSE Enterprise Linux Security Update for gstreamer-plugins-good (SUSE-SU-2022:2911-1)
- 752528 SUSE Enterprise Linux Security Update for gstreamer-plugins-good (SUSE-SU-2022:2957-1)
- 752771 SUSE Enterprise Linux Security Update for gstreamer-plugins-good (SUSE-SU-2022:3908-1)
- 754864 SUSE Enterprise Linux Security Update for gstreamer-plugins-good (SUSE-SU-2023:3688-1)
- 941005 AlmaLinux Security Update for gstreamer1-plugins-good (ALSA-2023:2260)