Denial of Service Risk in Bzip Decompression for GStreamer by Freedesktop
CVE-2022-1923
7.8HIGH
What is CVE-2022-1923?
The vulnerability presents a Denial of Service risk through an integer overflow in the matroskademux element during bzip decompression. This flaw could lead to a segmentation fault or a potential heap overwrite, dependent on the libc implementation and the capabilities of the operating system. If the libc uses mmap for large memory chunks and the OS supports it, a segmentation fault is likely. Conversely, if the libc does not utilize mmap or if the OS lacks mmap support, this could escalate to a heap overwrite, creating significant security implications for users.
Affected Version(s)
GStreamer 1.20.3