VDB

DEBIAN-CVE-2022-1925

DEBIAN-CVE-2022-1925 PUBLISHED CVSS 7.800000190734863 HIGH

DOS / potential heap overwrite in mkv demuxing using HEADERSTRIP decompression. Integer overflow in matroskaparse element in gst_matroska_decompress_data function which causes a heap overflow. Due to restrictions on chunk sizes in the matroskademux element, the overflow can't be triggered, however the matroskaparse element has no size checks.

Risk Scores

CVSS v3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Debian:13gst-plugins-good1.00, 0, 0
Debian:11gst-plugins-good1.00, 1.18.4-2, 1.18.4-2
Debian:12gst-plugins-good1.00, 0, 0
Debian:14gst-plugins-good1.00, 0, 0

Timeline

  • Jul 19, 2022 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›