CVE-2021-30473Release of Invalid Pointer or Reference in Aomedia

Severity
9.8CRITICALNVD
OSV6.5
EPSS
0.2%
top 52.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 6
Latest updateOct 23

Description

aom_image.c in libaom in AOMedia before 2021-04-07 frees memory that is not located on the heap.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

NVDaomedia/aomedia< 2021-04-07
debiandebian/aom< aom 3.2.0-1 (bookworm)

Also affects: Fedora 34

Patches

🔴Vulnerability Details

3
OSV
aom vulnerabilities2023-10-23
GHSA
GHSA-jr38-ch73-ccgx: aom_image2022-05-24
OSV
CVE-2021-30473: aom_image2021-05-06

📋Vendor Advisories

2
Ubuntu
AOM vulnerabilities2023-10-23
Debian
CVE-2021-30473: aom - aom_image.c in libaom in AOMedia before 2021-04-07 frees memory that is not loca...2021
CVE-2021-30473 — Aomedia vulnerability | cvebase