CVE-2021-3522
published 2021-06-02CVE-2021-3522: GStreamer before 1.18.4 may perform an out-of-bounds read when handling certain ID3v2 tags.
PriorityP424medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
5.37%
91.8th percentile
GStreamer before 1.18.4 may perform an out-of-bounds read when handling certain ID3v2 tags.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gst-plugins-base1.0 | < gst-plugins-base1.0 1.18.4-2 (bookworm) | gst-plugins-base1.0 1.18.4-2 (bookworm) |
| gstreamer | gstreamer | < 1.18.4 | 1.18.4 |
| gstreamer | gstreamer | — | — |
| netapp | e-series_santricity_os_controller | 11.0.0 – 11.70.1 | — |
| oracle | openjdk | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_oracle5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Java SE Risk Matrix: JavaFX (GStreamer) — CVE-2021-3522
vendor_oracle·2021-10-15·CVSS 5.5
CVE-2021-3522 [MEDIUM] Oracle Oracle Java SE Risk Matrix: JavaFX (GStreamer) — CVE-2021-3522
Oracle Oracle Java SE Risk Matrix: JavaFX (GStreamer) vulnerability
CVE: CVE-2021-3522
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuoct2021 (OCT 2021)
Ubuntu
GStreamer Base Plugins vulnerability
vendor_ubuntu·2021-05-18
CVE-2021-3522 GStreamer Base Plugins vulnerability
Title: GStreamer Base Plugins vulnerability
Summary: GStreamer Base Plugins could be made to expose sensitive information if it received
a specially crafted input.
It was discovered that GStreamer Base Plugins incorrectly handled certain inputs.
An attacker could possibly use this issue to expose sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
gstreamer-plugins-base: out-of-bounds read when handling certain ID3v2 tags
vendor_redhat·2021-03-15·CVSS 5.5
CVE-2021-3522 [MEDIUM] CWE-125 gstreamer-plugins-base: out-of-bounds read when handling certain ID3v2 tags
gstreamer-plugins-base: out-of-bounds read when handling certain ID3v2 tags
GStreamer before 1.18.4 may perform an out-of-bounds read when handling certain ID3v2 tags.
A flaw was found in gstreamer-plugins-base where an out-of-bounds read when handling certain ID3v2 tags is possible. The highest threat from this vulnerability is to system availability.
Package: gstreamer-plugins-base (Red Hat Enterprise Linux 6) - Out of support scope
Package: gstreamer-plugins-base (Red Hat Enterprise Linux 7) - Out of support scope
Debian
CVE-2021-3522: gst-plugins-base1.0 - GStreamer before 1.18.4 may perform an out-of-bounds read when handling certain ...
vendor_debian·2021·CVSS 5.5
CVE-2021-3522 [MEDIUM] CVE-2021-3522: gst-plugins-base1.0 - GStreamer before 1.18.4 may perform an out-of-bounds read when handling certain ...
GStreamer before 1.18.4 may perform an out-of-bounds read when handling certain ID3v2 tags.
Scope: local
bookworm: resolved (fixed in 1.18.4-2)
bullseye: resolved (fixed in 1.18.4-2)
forky: resolved (fixed in 1.18.4-2)
sid: resolved (fixed in 1.18.4-2)
trixie: resolved (fixed in 1.18.4-2)
GHSA
GHSA-x3cx-v22q-v4cr: GStreamer before 1
ghsa_unreviewed·2022-05-24
CVE-2021-3522 [MEDIUM] CWE-125 GHSA-x3cx-v22q-v4cr: GStreamer before 1
GStreamer before 1.18.4 may perform an out-of-bounds read when handling certain ID3v2 tags.
OSV
CVE-2021-3522: GStreamer before 1
osv·2021-06-02·CVSS 5.5
CVE-2021-3522 [MEDIUM] CVE-2021-3522: GStreamer before 1
GStreamer before 1.18.4 may perform an out-of-bounds read when handling certain ID3v2 tags.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1954761https://security.gentoo.org/glsa/202208-31https://security.netapp.com/advisory/ntap-20211022-0004/https://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1954761https://security.gentoo.org/glsa/202208-31https://security.netapp.com/advisory/ntap-20211022-0004/https://www.oracle.com/security-alerts/cpuoct2021.html
2021-06-02
Published