CVE-2022-1921: Integer Overflow
Published Jul 19, 2022
·Updated
Integer overflow in avidemux element in gstavidemuxinvert function which allows a heap overwrite while parsing avi files. Potential for arbitrary code execution through heap overwrite.
Affected Software
5 affected componentsFixes available
debian/gst-plugins-good1.0<=1.14.4-1+deb10u1
1.14.4-1+deb10u31.18.4-2+deb11u21.22.0-5+deb12u11.22.6-1
Gstreamer Project Gstreamer<1.20.3
Debian Debian Linux=10.0
Debian Debian Linux=11.0
GStreamer GStreamer<1.20.3
Remediation
Event History
Jul 19, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-1921.
2
What is the severity of CVE-2022-1921?
The severity of CVE-2022-1921 is high with a CVSS score of 7.8.
3
Which software is affected by CVE-2022-1921?
The Gstreamer project Gstreamer versions up to 1.20.3, Debian Linux 10.0, and Debian Linux 11.0 are affected by CVE-2022-1921.
4
How can an attacker exploit CVE-2022-1921?
An attacker can exploit CVE-2022-1921 by parsing malicious avi files, leading to a heap overwrite and potentially arbitrary code execution.
5
How can I mitigate CVE-2022-1921?
To mitigate CVE-2022-1921, update the affected software to the specified versions: Gstreamer up to 1.20.3, Debian Linux 10.0, and Debian Linux 11.0.