OESA-2021-1035
Dashboard / Vulnerabilities / OESA-2021-1035
Summary: gstreamer1-plugins-bad-free security update
Details: GStreamer is a pipeline-based multi media framework that links together a wide variety of media processing systems to complete complex workflows, based on graphs of filters which operate on media data. This package contains plug-ins that are not tested well enough yet, or the code is not of good enough quality.\r\n\r\n Security Fix(es):\r\n\r\n A flaw was found in the gstreamer h264 component of gst-plugins-bad before v1.18.1 where when parsing a h264 header, an attacker could cause the stack to be smashed, memory corruption and possibly code execution.(CVE-2021-3185)\r\n\r\n
References: https://openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1035, https://nvd.nist.gov/vuln/detail/CVE-2021-3185
Affected packages
Package
Name: gstreamer1-plugins-bad-free
Purl: pkg:rpm/openEuler/gstreamer1-plugins-bad-free&distro=openEuler-20.03-LTS
Affected ranges
Type: ECOSYSTEM
Events:
