GStreamer RealMedia File Parsing Integer Overflow Remote Code Execution Vulnerability
CVE-2023-38104

8.8HIGH

Key Information:

Vendor

Gstreamer

Status
Vendor
CVE Published:
3 May 2024

What is CVE-2023-38104?

The GStreamer Media Framework is susceptible to a vulnerability during the processing of RealMedia files, specifically in the parsing of MDPR chunks. The flaw arises from inadequate validation of input data, leading to an integer overflow condition prior to buffer allocation. This situation provides an opportunity for remote attackers to execute arbitrary code within the context of the affected process. Successful exploitation necessitates interaction with the GStreamer library, emphasizing the need for stringent security measures to mitigate the risk.

Affected Version(s)

GStreamer 1.22.3

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.