THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-53704 (HIGH 7.1) — A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a RealMedia file containing a specially crafted FILEINFO metadata section, the demuxer parses variable-name and variable-value pairs using re_skip_pascal_string() without validating

[NVD] CVE-2026-53704 (HIGH 7.1) — A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a RealMedia file containing a specially crafted FILEINFO metadata section, the demuxer parses variable-name and variable-value pairs using re_skip_pascal_string() without validating

lownvdPublished 2026-06-15

CVE-2026-53704 CVSS: 7.1 HIGH Published: 2026-06-15T20:16:33.697

A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a RealMedia file containing a specially crafted FILEINFO metadata section, the demuxer parses variable-name and variable-value pairs using re_skip_pascal_string() without validating that offsets remain within the mapped buffer. Additio

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-53704