Integer Overflow in Matroska Demuxer by GStreamer
CVE-2022-1920
7.8HIGH
What is CVE-2022-1920?
An integer overflow vulnerability exists in the matroskademux element of GStreamer. Specifically, in the function gst_matroska_demux_add_wvpk_header, improper handling of integer values can lead to a heap overwrite while processing matroska files. This vulnerability poses a significant risk as it may allow attackers to execute arbitrary code through the corrupted memory, potentially compromising system integrity and security.
Affected Version(s)
GStreamer 1.20.3