CVE-2022-1921
published 2022-07-19CVE-2022-1921: Integer overflow in avidemux element in gst_avi_demux_invert function which allows a heap overwrite while parsing avi files. Potential for arbitrary code…
PriorityP337high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.50%
39.9th percentile
Integer overflow in avidemux element in gst_avi_demux_invert function which allows a heap overwrite while parsing avi files. Potential for arbitrary code execution through heap overwrite.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | gst-plugins-good1.0 | < gst-plugins-good1.0 1.20.3-1 (bookworm) | gst-plugins-good1.0 1.20.3-1 (bookworm) |
| gstreamer | gstreamer | < 1.20.3 | 1.20.3 |
| gstreamer | gstreamer | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
gst-plugins-good1.0 vulnerabilities
osv·2022-08-08·CVSS 7.8
CVE-2022-1920 [HIGH] gst-plugins-good1.0 vulnerabilities
gst-plugins-good1.0 vulnerabilities
It was discovered that GStreamer Good Plugins incorrectly handled certain files.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2022-1920, CVE-2022-1921)
It was discovered that GStreamer Good Plugins incorrectly handled certain files.
An attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. (CVE-2022-1922, CVE-2022-1923, CVE-2022-1924,
CVE-2022-1925, CVE-2022-2122)
GHSA
GHSA-9427-ppcj-49fw: Integer overflow in avidemux element in gst_avi_demux_invert function which allows a heap overwrite while parsing avi files
ghsa_unreviewed·2022-07-20
CVE-2022-1921 [HIGH] CWE-190 GHSA-9427-ppcj-49fw: Integer overflow in avidemux element in gst_avi_demux_invert function which allows a heap overwrite while parsing avi files
Integer overflow in avidemux element in gst_avi_demux_invert function which allows a heap overwrite while parsing avi files. Potential for arbitrary code execution through heap overwrite.
OSV
CVE-2022-1921: Integer overflow in avidemux element in gst_avi_demux_invert function which allows a heap overwrite while parsing avi files
osv·2022-07-19·CVSS 7.8
CVE-2022-1921 [HIGH] CVE-2022-1921: Integer overflow in avidemux element in gst_avi_demux_invert function which allows a heap overwrite while parsing avi files
Integer overflow in avidemux element in gst_avi_demux_invert function which allows a heap overwrite while parsing avi files. Potential for arbitrary code execution through heap overwrite.
Ubuntu
GStreamer Good Plugins vulnerabilities
vendor_ubuntu·2022-08-08·CVSS 7.8
CVE-2022-1921 [HIGH] GStreamer Good Plugins vulnerabilities
Title: GStreamer Good Plugins vulnerabilities
Summary: Several security issues were fixed in GStreamer Plugins Good.
It was discovered that GStreamer Good Plugins incorrectly handled certain files.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2022-1920, CVE-2022-1921)
It was discovered that GStreamer Good Plugins incorrectly handled certain files.
An attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. (CVE-2022-1922, CVE-2022-1923, CVE-2022-1924,
CVE-2022-1925, CVE-2022-2122)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
gstreamer-plugins-good: Heap-based buffer overflow in the avi demuxer when handling certain AVI files
vendor_redhat·2022-05-17·CVSS 7.8
CVE-2022-1921 [HIGH] CWE-190 gstreamer-plugins-good: Heap-based buffer overflow in the avi demuxer when handling certain AVI files
gstreamer-plugins-good: Heap-based buffer overflow in the avi demuxer when handling certain AVI files
Integer overflow in avidemux element in gst_avi_demux_invert function which allows a heap overwrite while parsing avi files. Potential for arbitrary code execution through heap overwrite.
A flaw was found in GStreamer. An integer overflow can lead to a heap-based buffer overflow in the avi demuxer when processing a specially crafted AVI file. This vulnerability can result in application crash, memory corruption, and code execution.
Package: gstreamer-plugins-good (Red Hat Enterprise Linux 6) - Out of support scope
Package: gstreamer1-plugins-good (Red Hat Enterprise Linux 7) - Out of support scope
Package: gstreamer-plugins-good (Red Hat Enterprise Linux 7) - Out of support scope
Pac
Debian
CVE-2022-1921: gst-plugins-good1.0 - Integer overflow in avidemux element in gst_avi_demux_invert function which allo...
vendor_debian·2022·CVSS 7.8
CVE-2022-1921 [HIGH] CVE-2022-1921: gst-plugins-good1.0 - Integer overflow in avidemux element in gst_avi_demux_invert function which allo...
Integer overflow in avidemux element in gst_avi_demux_invert function which allows a heap overwrite while parsing avi files. Potential for arbitrary code execution through heap overwrite.
Scope: local
bookworm: resolved (fixed in 1.20.3-1)
bullseye: resolved (fixed in 1.18.4-2+deb11u1)
forky: resolved (fixed in 1.20.3-1)
sid: resolved (fixed in 1.20.3-1)
trixie: resolved (fixed in 1.20.3-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://gitlab.freedesktop.org/gstreamer/gstreamer/-/issues/1224https://lists.debian.org/debian-lts-announce/2022/08/msg00001.htmlhttps://www.debian.org/security/2022/dsa-5204https://gitlab.freedesktop.org/gstreamer/gstreamer/-/issues/1224https://lists.debian.org/debian-lts-announce/2022/08/msg00001.htmlhttps://www.debian.org/security/2022/dsa-5204
2022-07-19
Published