Denial of Service Vulnerability in GStreamer mkv Demuxing by Freedesktop
CVE-2022-1924

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
19 July 2022

What is CVE-2022-1924?

A denial of service vulnerability has been identified in the GStreamer mkv demuxing process due to an integer overflow in the lzo decompression function within the matroskademux element. This vulnerability can lead to a segfault or potentially overwrite the heap, depending on the memory management capabilities of the libc implementation and the underlying operating system. Specifically, if the system uses libc that employs mmap for managing memory chunks and that the operating system supports mmap, it will likely result in a segfault. In contrast, other scenarios where system constraints do not support these features can result in critical heap overwrites, risking application stability and exposing systems to further attacks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

GStreamer 1.20.3

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.