CyberRota Analysis
AI-GeneratedMKVToolNix versions up to 101.0 are vulnerable due to a heap buffer overflow in the avilib library's ODML superindex parser, stemming from integer wraparound in 32-bit arithmetic. This vulnerability allows attackers to create malicious AVI files that exploit undersized heap allocations, potentially leading to arbitrary code execution. Users and organizations utilizing MKVToolNix for media processing should prioritize patching to mitigate this high-severity risk.
Original NVD Description
MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI file with oversized entry counts that cause an undersized heap allocation, allowing a heap buffer overflow when the file is parsed with mkvmerge.