Impact
GStreamer is vulnerable to an out‑of‑bounds write in the MRF file parser. The flaw arises because the parser does not properly validate user‑supplied data, allowing an attacker to write data past the end of a buffer. This can lead to arbitrary code execution in the context of the process that parses the file.
Affected Systems
The vulnerability affects all GStreamer installations that support MRF files. No specific product or version ranges are disclosed, so any system running an affected version of GStreamer can be compromised. Systems with the MRF plugin enabled are at greatest risk.
Risk and Exploitability
The CVSS score is 7.8, indicating high risk. EPSS data is not available, and the issue is not listed in KEV. Exploitation requires user interaction – the target must open a malicious MRF file or visit a page that triggers parsing. While the attack surface is limited to individuals who inadvertently expose the system to a malicious file or web page, the ability to execute arbitrary code makes the risk significant for environments where users view untrusted content.
OpenCVE Enrichment