GStreamer gst-plugins-good
cpe:2.3:a:gstreamer:gstreamer:*:*:*:*:*:*:*, +2 more
- < 1.28.2
A denial-of-service vulnerability has been identified in GStreamer gst-plugins-good versions prior to 1.28.2. The issue arises in the isomp4 plugin's qtdemux_parse_trak function, which fails to properly validate atom data when parsing MP4 audio tracks. This lack of validation allows for division operations to be performed on zero values, leading to integer division by zero and causing application crashes.
Exploitation of this vulnerability leads to a crash of the application. The out-of-bounds reads could potentially allow for information disclosure.
Users can upgrade to GStreamer gst-plugins-good version 1.28.2 or apply the available patch and recompile.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.