GStreamer FLAC File Parsing Integer Overflow Remote Code Execution Vulnerability
CVE-2023-37327

8.8HIGH

Key Information:

Vendor

Gstreamer

Status
Vendor
CVE Published:
3 May 2024

What is CVE-2023-37327?

A vulnerability within the GStreamer Media Framework specifically affects the parsing of FLAC audio files, allowing remote attackers to execute arbitrary code. The flaw arises due to improper validation of user-supplied data. When a specially crafted FLAC file is processed, it can lead to an integer overflow prior to buffer allocation. This may allow an attacker to gain control over the execution context of the current process, with attack vectors varying based on implementation. Protection against potential exploits should be prioritized by updating to the latest GStreamer versions.

Affected Version(s)

GStreamer 1.22.1

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.