GStreamer MXF File Parsing Integer Overflow Remote Code Execution Vulnerability
CVE-2023-40474 
What is CVE-2023-40474?
A vulnerability exists in the GStreamer library related to the parsing of MXF video files. This flaw occurs due to improper validation of user-supplied data, resulting in an integer overflow prior to buffer allocation. As a consequence, this can enable remote attackers to execute arbitrary code on affected installations of GStreamer. Successful exploitation requires interaction with the library, and while attack vectors may vary based on implementation, the potential for code execution within the context of the current process poses a significant risk to system integrity. For more details, refer to the advisories from the Zero Day Initiative and GStreamer security announcements.
Affected Version(s)
GStreamer 1.22.4 and 8dddb9ad2009705dfc3e50d59d7c56fc7314cfc3
References
EPSS Score
6% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
