CVE-2022-2122
Summary
| CVE | CVE-2022-2122 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-07-19 20:15:00 UTC |
| Updated | 2022-10-07 14:05:00 UTC |
| Description | DOS / potential heap overwrite in qtdemux using zlib decompression. Integer overflow in qtdemux element in qtdemux_inflate function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities, it could be just a segfault or a heap overwrite. |
Risk And Classification
Problem Types: CWE-787 | CWE-190
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 11.0 | All | All | All |
| Application | Gstreamer Project | Gstreamer | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| matroska: segfault / potential heap overflow in zlib decoding (#1225) · Issues · GStreamer / gstreamer · GitLab | MISC | gitlab.freedesktop.org | |
| [SECURITY] [DLA 3069-1] gst-plugins-good1.0 security update | MLIST | lists.debian.org | |
| Debian -- Security Information -- DSA-5204-1 gst-plugins-good1.0 | DEBIAN | www.debian.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160615 Oracle Enterprise Linux Security Update for gstreamer1-plugins-good (ELSA-2023-2260)
- 180925 Debian Security Update for gst-plugins-good1.0 (DLA 3069-1)
- 180926 Debian Security Update for gst-plugins-good1.0 (DSA 5204-1)
- 182571 Debian Security Update for gst-plugins-good1.0 (CVE-2022-2122)
- 198890 Ubuntu Security Notification for GStreamer Good Plugins Vulnerabilities (USN-5555-1)
- 241421 Red Hat Update for gstreamer1-plugins-good (RHSA-2023:2260)
- 503597 Alpine Linux Security Update for gst-plugins-good
- 506095 Alpine Linux Security Update for gst-plugins-good
- 672070 EulerOS Security Update for gstreamer1-plugins-good (EulerOS-SA-2022-2269)
- 672187 EulerOS Security Update for gstreamer1-plugins-good (EulerOS-SA-2022-2463)
- 752512 SUSE Enterprise Linux Security Update for gstreamer-plugins-good (SUSE-SU-2022:2911-1)
- 752528 SUSE Enterprise Linux Security Update for gstreamer-plugins-good (SUSE-SU-2022:2957-1)
- 752771 SUSE Enterprise Linux Security Update for gstreamer-plugins-good (SUSE-SU-2022:3908-1)
- 754864 SUSE Enterprise Linux Security Update for gstreamer-plugins-good (SUSE-SU-2023:3688-1)
- 941005 AlmaLinux Security Update for gstreamer1-plugins-good (ALSA-2023:2260)