GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
CVE-2023-50186
What is CVE-2023-50186?
A vulnerability exists in the GStreamer Media Framework related to the parsing of AV1 encoded video files. The flaw arises from insufficient validation of the user-supplied data length before it is copied to a fixed-length stack-based buffer. This weakness enables remote attackers to potentially execute arbitrary code within the current process context by exploiting the metadata parsing errors, thereby compromising system integrity. Interaction with the affected GStreamer installations is necessary for successful exploitation. Comprehensive patching and detection strategies are recommended to mitigate risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
GStreamer bd4a9fde89e2549887e8a77d22ab027bed70d743
References
EPSS Score
9% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
