VDB
DEBIAN-CVE-2022-1925
DEBIAN-CVE-2022-1925
PUBLISHED
CVSS 7.800000190734863 HIGH
DOS / potential heap overwrite in mkv demuxing using HEADERSTRIP decompression. Integer overflow in matroskaparse element in gst_matroska_decompress_data function which causes a heap overflow. Due to restrictions on chunk sizes in the matroskademux element, the overflow can't be triggered, however the matroskaparse element has no size checks.
Risk Scores
CVSS v3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:13 | gst-plugins-good1.0 | 0, 0, 0 |
| Debian:11 | gst-plugins-good1.0 | 0, 1.18.4-2, 1.18.4-2 |
| Debian:12 | gst-plugins-good1.0 | 0, 0, 0 |
| Debian:14 | gst-plugins-good1.0 | 0, 0, 0 |
Timeline
- Jul 19, 2022 CVE Published
- Apr 28, 2026 CVE Updated