Impact
A flaw in GStreamer gst-plugins-good’s avidemux parser can allow a crafted AVI file to trigger an out-of-bounds read during parsing of the vprp video field descriptor. The excess descriptor count causes the parser to read beyond the limits of the supplied buffer, which can crash the process that invokes playbin or decodebin. The crash results in a denial of service because the media handling application becomes unavailable until restarted.
Affected Systems
The vulnerability affects the avidemux component of GStreamer gst-plugins-good, including versions installed on Red Hat Enterprise Linux 10, 7, 8, and 9. Organizations using older releases of gst-plugins-good that have not yet applied the upstream fix are impacted.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity. No EPSS score is currently available, and the vulnerability is not listed in the CISA KEV catalog, meaning there is no evidence of known exploitation in the wild at this time. An attacker would need to get the vulnerable application to process a malicious AVI file, which could be achieved locally or potentially remotely if the media content is accepted from an untrusted source. Because the impact is limited to application crash rather than arbitrary code execution or data disclosure, the risk is primarily to availability and depends on the operational context of the affected services.
OpenCVE Enrichment