Buffer Overflow Vulnerability in GStreamer Affects Multiple Versions
CVE-2025-47219

8.1HIGH

Key Information:

Vendor

GStreamer

Status
Vendor
CVE Published:
7 August 2025

What is CVE-2025-47219?

In versions of GStreamer up to 1.26.1, a vulnerability exists within the isomp4 plugin's qtdemux_parse_trak function, which can lead to a situation where the function reads beyond the bounds of a heap buffer while processing an MP4 file. This flaw may potentially allow unauthorized access to sensitive information, posing a significant risk for applications relying on MP4 file handling.

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.