CVE-2025-47219

EUVD-2025-23945
In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_trak function may read past the end of a heap buffer while parsing an MP4 file, possibly leading to information disclosure.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
siemens-SADPADP
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 34%
Affected Products (NVD)
VendorProductVersion
gstreamergstreamer
𝑥
< 1.26.2
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
SiemensSIMATIC CN 4100
𝑥
< V5.0
ADP
siemenssimatic_cn_4100
𝑥
< 5.0
ADP
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
gstreamer-plugins-good
suse enterprise desktop 15 SP6
1.24.0-150600.3.7.1
fixed
suse enterprise desktop 15 SP7
1.24.0-150600.3.7.1
fixed
suse enterprise sap 15 SP6
1.24.0-150600.3.7.1
fixed
suse enterprise sap 15 SP7
1.24.0-150600.3.7.1
fixed
suse enterprise server 15 SP4
1.20.1-150400.3.14.1
fixed
suse enterprise server 15 SP5
1.22.0-150500.4.10.1
fixed
suse enterprise server 15 SP6
1.24.0-150600.3.7.1
fixed
suse enterprise server 15 SP7
1.24.0-150600.3.7.1
fixed
gstreamer-plugins-good-lang
suse enterprise desktop 15 SP6
1.24.0-150600.3.7.1
fixed
suse enterprise desktop 15 SP7
1.24.0-150600.3.7.1
fixed
suse enterprise sap 15 SP6
1.24.0-150600.3.7.1
fixed
suse enterprise sap 15 SP7
1.24.0-150600.3.7.1
fixed
suse enterprise server 15 SP4
1.20.1-150400.3.14.1
fixed
suse enterprise server 15 SP5
1.22.0-150500.4.10.1
fixed
suse enterprise server 15 SP6
1.24.0-150600.3.7.1
fixed
suse enterprise server 15 SP7
1.24.0-150600.3.7.1
fixed