GStreamer H265 Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
CVE-2023-40476 
What is CVE-2023-40476?
A vulnerability has been identified within the GStreamer library that affects its handling of H265 encoded video files. The flaw is due to inadequate validation of the length of user-supplied data, which occurs before it is copied to a fixed-length stack-based buffer. This oversight can be exploited by remote attackers who can execute arbitrary code in the context of the current process. To successfully exploit this vulnerability, interaction with the GStreamer library is necessary, making the attack vectors dependent on the implementation. Users of GStreamer should take precautions to mitigate potential risks associated with this vulnerability.
Affected Version(s)
GStreamer 1.22.4 and 8dddb9ad2009705dfc3e50d59d7c56fc7314cfc3
References
EPSS Score
8% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
