{
  "threat_severity" : "Moderate",
  "public_date" : "2025-08-07T00:00:00Z",
  "bugzilla" : {
    "description" : "gstreamer1-plugins-good: GStreamer MP4 Parser Heap Overflow",
    "id" : "2387141",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2387141"
  },
  "cvss3" : {
    "cvss3_base_score" : "5.6",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
    "status" : "draft"
  },
  "cwe" : "CWE-125",
  "details" : [ "In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_tree function may read past the end of a heap buffer while parsing an MP4 file, leading to information disclosure.", "A flaw was found in gstreamer1-plugins-good. The isomp4 plugin's qtdemux_parse_tree function incorrectly handles MP4 file parsing, resulting in a heap buffer over-read. This flaw allows a local attacker to trigger this vulnerability by providing a specially crafted MP4 file. This over-read can lead to information disclosure." ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "fix_state" : "Fix deferred",
    "package_name" : "gstreamer1-plugins-good",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Fix deferred",
    "package_name" : "gstreamer1-plugins-good",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Fix deferred",
    "package_name" : "gstreamer1-plugins-good",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Fix deferred",
    "package_name" : "gstreamer1-plugins-good",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2025-47183\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-47183\nhttps://github.com/atredispartners/advisories/blob/master/2025/ATREDIS-2025-0003.md\nhttps://gstreamer.freedesktop.org/security/" ],
  "name" : "CVE-2025-47183",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}