Impact
Multiple integer overflow and underflow conditions exist in GStreamer's ASF demuxer used by the gst-plugins-ugly package. When parsing crafted ASF, WMV, or WMA files, untrusted length and size values bypass bounds checks, enabling out-of-bounds heap reads. This can cause the application to crash, resulting in denial of service, or reveal limited memory contents that may disclose sensitive information. The weakness corresponds to CWE-190, an improper validation of numeric values.
Affected Systems
The vulnerability affects Red Hat Enterprise Linux releases 7, 8, 9, and 10 that include the GStreamer gst-plugins-ugly bundle. The impacted component is the ASF demuxer (asfdemux) within the gst-plugins-ugly package. No specific product or version range is provided beyond the entire RHEL family; administrators should check installed GStreamer versions and verify deployments of this plugin.
Risk and Exploitability
The CVSS score of 7.1 places the flaw in the high‑severity range, and the EPSS score is currently unspecified. Because the issue requires an attacker to supply a malformed media file to a vulnerable application, the likely attack vector is local or remote file injection, depending on the application context. The flaw is not listed in the CISA KEV catalog, and no exploit or workaround is announced by Red Hat. As a result, the risk depends on the exposure of applications that process ASF, WMV, or WMA files, but no privileged escalation or remote code execution is described.
OpenCVE Enrichment