GStreamer SRT File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
CVE-2023-37329

8.8HIGH

Key Information:

Vendor

Gstreamer

Status
Vendor
CVE Published:
3 May 2024

What is CVE-2023-37329?

A vulnerability exists in the GStreamer library that involves a heap-based buffer overflow during the parsing of SRT subtitle files. This flaw arises from inadequate validation of the user-supplied data length, leading to potential arbitrary code execution within the context of the current process when exploited. Attackers must interact with the library to leverage this vulnerability, but the specific attack vectors may differ based on individual implementations. Users using affected versions are advised to apply security patches and follow best practices to mitigate risks associated with this vulnerability.

Affected Version(s)

GStreamer 1.22.2

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.