CVE-2022-2122
published 2022-07-19CVE-2022-2122: DOS / potential heap overwrite in qtdemux using zlib decompression. Integer overflow in qtdemux element in qtdemux_inflate function which causes a segfault, or…
PriorityP336high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.45%
37.0th percentile
DOS / potential heap overwrite in qtdemux using zlib decompression. Integer overflow in qtdemux element in qtdemux_inflate function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities, it could be just a segfault or a heap overwrite.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | gst-plugins-good1.0 | < gst-plugins-good1.0 1.20.3-1 (bookworm) | gst-plugins-good1.0 1.20.3-1 (bookworm) |
| gstreamer | gstreamer | < 1.20.3 | 1.20.3 |
| gstreamer | gstreamer | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
gst-plugins-good1.0 vulnerabilities
osv·2022-08-08·CVSS 7.8
CVE-2022-1920 [HIGH] gst-plugins-good1.0 vulnerabilities
gst-plugins-good1.0 vulnerabilities
It was discovered that GStreamer Good Plugins incorrectly handled certain files.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2022-1920, CVE-2022-1921)
It was discovered that GStreamer Good Plugins incorrectly handled certain files.
An attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. (CVE-2022-1922, CVE-2022-1923, CVE-2022-1924,
CVE-2022-1925, CVE-2022-2122)
GHSA
GHSA-qc68-fgqr-q53f: DOS / potential heap overwrite in qtdemux using zlib decompression
ghsa_unreviewed·2022-07-20
CVE-2022-2122 [HIGH] CWE-122 GHSA-qc68-fgqr-q53f: DOS / potential heap overwrite in qtdemux using zlib decompression
DOS / potential heap overwrite in qtdemux using zlib decompression. Integer overflow in qtdemux element in qtdemux_inflate function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities, it could be just a segfault or a heap overwrite.
OSV
CVE-2022-2122: DOS / potential heap overwrite in qtdemux using zlib decompression
osv·2022-07-19·CVSS 7.8
CVE-2022-2122 [HIGH] CVE-2022-2122: DOS / potential heap overwrite in qtdemux using zlib decompression
DOS / potential heap overwrite in qtdemux using zlib decompression. Integer overflow in qtdemux element in qtdemux_inflate function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities, it could be just a segfault or a heap overwrite.
Ubuntu
GStreamer Good Plugins vulnerabilities
vendor_ubuntu·2022-08-08·CVSS 7.8
CVE-2022-1921 [HIGH] GStreamer Good Plugins vulnerabilities
Title: GStreamer Good Plugins vulnerabilities
Summary: Several security issues were fixed in GStreamer Plugins Good.
It was discovered that GStreamer Good Plugins incorrectly handled certain files.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2022-1920, CVE-2022-1921)
It was discovered that GStreamer Good Plugins incorrectly handled certain files.
An attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. (CVE-2022-1922, CVE-2022-1923, CVE-2022-1924,
CVE-2022-1925, CVE-2022-2122)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
gstreamer-plugins-good: Potential heap overwrite in mp4 demuxing using zlib decompression
vendor_redhat·2022-05-18·CVSS 7.8
CVE-2022-2122 [HIGH] CWE-190 gstreamer-plugins-good: Potential heap overwrite in mp4 demuxing using zlib decompression
gstreamer-plugins-good: Potential heap overwrite in mp4 demuxing using zlib decompression
DOS / potential heap overwrite in qtdemux using zlib decompression. Integer overflow in qtdemux element in qtdemux_inflate function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities, it could be just a segfault or a heap overwrite.
A flaw was found in GStreamer. An integer overflow can lead to a heap-based buffer overflow in the qt demuxer when processing a specially crafted QuickTime/MP4 file using zlib decompression. This vulnerability can result in application crash, memory corruption, and code execution.
Package: gstreamer-plugins-good (Red Hat Enterprise Linux 6) - Out of support scope
Package: gs
Debian
CVE-2022-2122: gst-plugins-good1.0 - DOS / potential heap overwrite in qtdemux using zlib decompression. Integer over...
vendor_debian·2022·CVSS 7.8
CVE-2022-2122 [HIGH] CVE-2022-2122: gst-plugins-good1.0 - DOS / potential heap overwrite in qtdemux using zlib decompression. Integer over...
DOS / potential heap overwrite in qtdemux using zlib decompression. Integer overflow in qtdemux element in qtdemux_inflate function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities, it could be just a segfault or a heap overwrite.
Scope: local
bookworm: resolved (fixed in 1.20.3-1)
bullseye: resolved (fixed in 1.18.4-2+deb11u1)
forky: resolved (fixed in 1.20.3-1)
sid: resolved (fixed in 1.20.3-1)
trixie: resolved (fixed in 1.20.3-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://gitlab.freedesktop.org/gstreamer/gstreamer/-/issues/1225https://lists.debian.org/debian-lts-announce/2022/08/msg00001.htmlhttps://www.debian.org/security/2022/dsa-5204https://gitlab.freedesktop.org/gstreamer/gstreamer/-/issues/1225https://lists.debian.org/debian-lts-announce/2022/08/msg00001.htmlhttps://www.debian.org/security/2022/dsa-5204
2022-07-19
Published