UBUNTU-CVE-2022-1925
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-1925
UBUNTU-CVE-2022-1925
Summary:
Details: DOS / potential heap overwrite in mkv demuxing using HEADERSTRIP decompression. Integer overflow in matroskaparse element in gst_matroska_decompress_data function which causes a heap overflow. Due to restrictions on chunk sizes in the matroskademux element, the overflow can't be triggered, however the matroskaparse element has no size checks.
References: https://ubuntu.com/security/CVE-2022-1925, https://gitlab.freedesktop.org/gstreamer/gstreamer/-/issues/1225, https://ubuntu.com/security/notices/USN-5555-1, https://www.cve.org/CVERecord?id=CVE-2022-1925
Affected packages
Package
Name: gst-plugins-good1.0
Purl: pkg:deb/ubuntu/[email protected]+esm1?arch=source&distro=esm-infra/xenial
Affected ranges
Type: ECOSYSTEM
Events:
