UBUNTU-CVE-2021-3522
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-3522
UBUNTU-CVE-2021-3522
Summary:
Details: GStreamer before 1.18.4 may perform an out-of-bounds read when handling certain ID3v2 tags.
References: https://ubuntu.com/security/CVE-2021-3522, https://gitlab.freedesktop.org/gstreamer/gst-plugins-base/-/issues/876, https://gitlab.freedesktop.org/gstreamer/gst-plugins-base/-/commit/f4a1428a6997658625d529b9db60fde812fbf1ee, https://gitlab.freedesktop.org/gstreamer/gst-plugins-base/-/commit/8a88e5c1db05ebadfd4569955f6f47c23cdca3c4, https://gstreamer.freedesktop.org/security/sa-2021-0001.html, https://ubuntu.com/security/notices/USN-4959-1, https://www.cve.org/CVERecord?id=CVE-2021-3522
Affected packages
Package
Name: gst-plugins-base1.0
Purl: pkg:deb/ubuntu/gst-plugins-base1.0?arch=source&distro=esm-infra%2Fxenial
Affected ranges
Type: ECOSYSTEM
Events:
