Advisories ยป MGASA-2021-0334

Updated gstreamer1.0-plugins packages fix security vulnerabilities

Publication date: 10 Jul 2021
Modification date: 10 Jul 2021
Type: security
Affected Mageia releases : 7 , 8
CVE: CVE-2021-3522

Description

GStreamer before 1.18.4 may perform an out-of-bounds read when handling certain
ID3v2 tags (CVE-2021-3522).

Overflows in AVC/HEVC NAL unit length calculations, which would lead to
allocating infinite amounts of small memory blocks until OOM and could
potentially also lead to memory corruptions.
                

References

SRPMS

8/tainted

8/core

7/core

7/tainted