CVE-2021-3498Improper Restriction of Operations within the Bounds of a Memory Buffer in Gstreamer

Severity
7.8HIGHNVD
EPSS
0.2%
top 53.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 19
Latest updateMay 24

Description

GStreamer before 1.18.4 might cause heap corruption when parsing certain malformed Matroska files.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

NVDgstreamer/gstreamer1.0.01.18.4
debiandebian/gst-plugins-good1.0< gst-plugins-good1.0 1.18.4-2 (bookworm)

Also affects: Debian Linux 10.0, Enterprise Linux 7.0, 8.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-hf4m-4x6v-4wvr: GStreamer before 12022-05-24
OSV
gst-plugins-good1.0 vulnerabilities2021-04-28
OSV
CVE-2021-3498: GStreamer before 12021-04-19

📋Vendor Advisories

3
Ubuntu
GStreamer Good Plugins vulnerabilities2021-04-28
Red Hat
gstreamer-plugins-good: Heap corruption in matroska demuxing2021-03-15
Debian
CVE-2021-3498: gst-plugins-good1.0 - GStreamer before 1.18.4 might cause heap corruption when parsing certain malform...2021
CVE-2021-3498 — Gstreamer vulnerability | cvebase