Miggo Logo

CVE-2022-24902: tkvideo has a memory issue in playing videos

4.3

CVSS Score
3.1

Basic Information

EPSS Score
0.35209%
Published
5/3/2022
Updated
2/1/2023
KEV Status
No
Technology
TechnologyPython

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Package NameEcosystemVulnerable VersionsFirst Patched Version
tkvideoplayerpip< 2.0.02.0.0

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis

The provided information lacks concrete technical details about the implementation. While the vulnerability (CWE-400) clearly indicates uncontrolled memory consumption during video playback, none of the sources explicitly identify specific functions or code paths responsible. The GitHub advisory, NVD description, and related issues only describe the symptom (memory bloat) and patched version, but no commit diffs, code snippets, or technical analysis of the memory management flaw are available. Without access to pre-2.0.0 code or patch details, we cannot confidently map the vulnerability to specific functions while maintaining factual accuracy.

Vulnerable functions

Only Mi**o us*rs **n s** t*is s**tion

WAF Protection Rules

WAF Rule

*u** m*mory *onsumption *v*n w**n pl*yin* sm*ll *il*s. T*is issu* **s ***n p*t**** in *.*.*. Pl**s* up*r*** to v*rsion *.*.* or **ov*.

Reasoning

T** provi*** in*orm*tion l**ks *on*r*t* t***ni**l **t*ils **out t** impl*m*nt*tion. W*il* t** vuln*r**ility (*W*-***) *l**rly in*i**t*s un*ontroll** m*mory *onsumption *urin* vi**o pl*y***k, non* o* t** sour**s *xpli*itly i**nti*y sp**i*i* *un*tions