GStreamer FLAC File Parsing Integer Overflow Remote Code Execution Vulnerability
CVE-2023-37327 
8.8HIGH
What is CVE-2023-37327?
A vulnerability within the GStreamer Media Framework specifically affects the parsing of FLAC audio files, allowing remote attackers to execute arbitrary code. The flaw arises due to improper validation of user-supplied data. When a specially crafted FLAC file is processed, it can lead to an integer overflow prior to buffer allocation. This may allow an attacker to gain control over the execution context of the current process, with attack vectors varying based on implementation. Protection against potential exploits should be prioritized by updating to the latest GStreamer versions.
Affected Version(s)
GStreamer 1.22.1
