CVE-2022-1925: Integer Overflow
DOS / potential heap overwrite in mkv demuxing using HEADERSTRIP decompression. Integer overflow in matroskaparse element in gstmatroskadecompressdata function which causes a heap overflow. Due to restrictions on chunk sizes in the matroskademux element, the overflow can't be triggered, however the matroskaparse element has no size checks.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-1925.
What is the severity of CVE-2022-1925?
CVE-2022-1925 has a severity rating of 7.8 (high).
What is the affected software?
The affected software includes Gstreamer Project Gstreamer versions up to and excluding 1.20.3, Debian Debian Linux version 10.0, and Debian Debian Linux version 11.0.
How does CVE-2022-1925 affect Gstreamer?
CVE-2022-1925 is a DOS vulnerability that can potentially lead to a heap overwrite in mkv demuxing using HEADERSTRIP decompression in Gstreamer.
How do I fix CVE-2022-1925?
To fix CVE-2022-1925, update to Gstreamer version 1.20.3 or later, or apply the appropriate security fixes provided by the Debian project.