CVE-2022-1920
published 2022-07-19CVE-2022-1920: Integer overflow in matroskademux element in gst_matroska_demux_add_wvpk_header function which allows a heap overwrite while parsing matroska files. Potential…
PriorityP337high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.50%
39.9th percentile
Integer overflow in matroskademux element in gst_matroska_demux_add_wvpk_header function which allows a heap overwrite while parsing matroska files. Potential for arbitrary code execution through heap overwrite.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | gst-plugins-good1.0 | < gst-plugins-good1.0 1.20.3-1 (bookworm) | gst-plugins-good1.0 1.20.3-1 (bookworm) |
| gstreamer | gstreamer | < 1.20.3 | 1.20.3 |
| gstreamer | gstreamer | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GStreamer Good Plugins vulnerabilities
vendor_ubuntu·2022-08-08·CVSS 7.8
CVE-2022-1921 [HIGH] GStreamer Good Plugins vulnerabilities
Title: GStreamer Good Plugins vulnerabilities
Summary: Several security issues were fixed in GStreamer Plugins Good.
It was discovered that GStreamer Good Plugins incorrectly handled certain files.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2022-1920, CVE-2022-1921)
It was discovered that GStreamer Good Plugins incorrectly handled certain files.
An attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. (CVE-2022-1922, CVE-2022-1923, CVE-2022-1924,
CVE-2022-1925, CVE-2022-2122)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
gstreamer-plugins-good: Potential heap overwrite in gst_matroska_demux_add_wvpk_header()
vendor_redhat·2022-05-18·CVSS 7.8
CVE-2022-1920 [HIGH] CWE-190 gstreamer-plugins-good: Potential heap overwrite in gst_matroska_demux_add_wvpk_header()
gstreamer-plugins-good: Potential heap overwrite in gst_matroska_demux_add_wvpk_header()
Integer overflow in matroskademux element in gst_matroska_demux_add_wvpk_header function which allows a heap overwrite while parsing matroska files. Potential for arbitrary code execution through heap overwrite.
A flaw was found in GStreamer. An integer overflow can lead to a heap-based buffer overflow in the mkv demuxer when processing a specially crafted Matroska file. This vulnerability can result in application crash, memory corruption, and code execution.
Package: gstreamer-plugins-good (Red Hat Enterprise Linux 6) - Out of support scope
Package: gstreamer1-plugins-good (Red Hat Enterprise Linux 7) - Out of support scope
Package: gstreamer-plugins-good (Red Hat Enterprise Linux 7) - Out of su
Debian
CVE-2022-1920: gst-plugins-good1.0 - Integer overflow in matroskademux element in gst_matroska_demux_add_wvpk_header ...
vendor_debian·2022·CVSS 7.8
CVE-2022-1920 [HIGH] CVE-2022-1920: gst-plugins-good1.0 - Integer overflow in matroskademux element in gst_matroska_demux_add_wvpk_header ...
Integer overflow in matroskademux element in gst_matroska_demux_add_wvpk_header function which allows a heap overwrite while parsing matroska files. Potential for arbitrary code execution through heap overwrite.
Scope: local
bookworm: resolved (fixed in 1.20.3-1)
bullseye: resolved (fixed in 1.18.4-2+deb11u1)
forky: resolved (fixed in 1.20.3-1)
sid: resolved (fixed in 1.20.3-1)
trixie: resolved (fixed in 1.20.3-1)
OSV
gst-plugins-good1.0 vulnerabilities
osv·2022-08-08·CVSS 7.8
CVE-2022-1920 [HIGH] gst-plugins-good1.0 vulnerabilities
gst-plugins-good1.0 vulnerabilities
It was discovered that GStreamer Good Plugins incorrectly handled certain files.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2022-1920, CVE-2022-1921)
It was discovered that GStreamer Good Plugins incorrectly handled certain files.
An attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. (CVE-2022-1922, CVE-2022-1923, CVE-2022-1924,
CVE-2022-1925, CVE-2022-2122)
GHSA
GHSA-hvfw-pcx7-j7qm: Integer overflow in matroskademux element in gst_matroska_demux_add_wvpk_header function which allows a heap overwrite while parsing matroska files
ghsa_unreviewed·2022-07-20
CVE-2022-1920 [HIGH] CWE-122 GHSA-hvfw-pcx7-j7qm: Integer overflow in matroskademux element in gst_matroska_demux_add_wvpk_header function which allows a heap overwrite while parsing matroska files
Integer overflow in matroskademux element in gst_matroska_demux_add_wvpk_header function which allows a heap overwrite while parsing matroska files. Potential for arbitrary code execution through heap overwrite.
OSV
CVE-2022-1920: Integer overflow in matroskademux element in gst_matroska_demux_add_wvpk_header function which allows a heap overwrite while parsing matroska files
osv·2022-07-19·CVSS 7.8
CVE-2022-1920 [HIGH] CVE-2022-1920: Integer overflow in matroskademux element in gst_matroska_demux_add_wvpk_header function which allows a heap overwrite while parsing matroska files
Integer overflow in matroskademux element in gst_matroska_demux_add_wvpk_header function which allows a heap overwrite while parsing matroska files. Potential for arbitrary code execution through heap overwrite.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://gitlab.freedesktop.org/gstreamer/gstreamer/-/issues/1226https://lists.debian.org/debian-lts-announce/2022/08/msg00001.htmlhttps://www.debian.org/security/2022/dsa-5204https://gitlab.freedesktop.org/gstreamer/gstreamer/-/issues/1226https://lists.debian.org/debian-lts-announce/2022/08/msg00001.htmlhttps://www.debian.org/security/2022/dsa-5204
2022-07-19
Published