CVE-2025-47183

In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_tree function may read past the end of a heap buffer while parsing an MP4 file, leading to information disclosure.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gstreamer_project:gstreamer:*:*:*:*:*:*:*:*

History

12 Aug 2025, 16:40

Type Values Removed Values Added
First Time Gstreamer Project gstreamer
Gstreamer Project
CPE cpe:2.3:a:gstreamer_project:gstreamer:*:*:*:*:*:*:*:*
References () https://github.com/atredispartners/advisories/blob/master/2025/ATREDIS-2025-0003.md - () https://github.com/atredispartners/advisories/blob/master/2025/ATREDIS-2025-0003.md - Exploit, Third Party Advisory
References () https://gstreamer.freedesktop.org/security/ - () https://gstreamer.freedesktop.org/security/ - Vendor Advisory

11 Aug 2025, 21:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.6
CWE CWE-125
References () https://github.com/atredispartners/advisories/blob/master/2025/ATREDIS-2025-0003.md - () https://github.com/atredispartners/advisories/blob/master/2025/ATREDIS-2025-0003.md -
Summary
  • (es) En GStreamer hasta la versión 1.26.1, la función qtdemux_parse_tree del complemento isomp4 puede leer más allá del final de un búfer de montón mientras analiza un archivo MP4, lo que provoca la divulgación de información.

07 Aug 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-07 20:15

Updated : 2025-08-12 16:40


NVD link : CVE-2025-47183

Mitre link : CVE-2025-47183

CVE.ORG link : CVE-2025-47183


JSON object : View

Products Affected

gstreamer_project

  • gstreamer
CWE
CWE-125

Out-of-bounds Read