Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-3185

Опубликовано: 26 янв. 2021
Источник: debian

Описание

A flaw was found in the gstreamer h264 component of gst-plugins-bad before v1.18.1 where when parsing a h264 header, an attacker could cause the stack to be smashed, memory corruption and possibly code execution.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gst-plugins-bad1.0fixed1.18.1-1package

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1917192

  • https://gitlab.freedesktop.org/gstreamer/gst-plugins-bad/-/commit/11353b3f6e2f047cc37483d21e6a37ae558896bc

  • https://www.openwall.com/lists/oss-security/2021/01/20/1

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 5 лет назад

A flaw was found in the gstreamer h264 component of gst-plugins-bad before v1.18.1 where when parsing a h264 header, an attacker could cause the stack to be smashed, memory corruption and possibly code execution.

CVSS3: 7.3
redhat
больше 5 лет назад

A flaw was found in the gstreamer h264 component of gst-plugins-bad before v1.18.1 where when parsing a h264 header, an attacker could cause the stack to be smashed, memory corruption and possibly code execution.

CVSS3: 9.8
nvd
около 5 лет назад

A flaw was found in the gstreamer h264 component of gst-plugins-bad before v1.18.1 where when parsing a h264 header, an attacker could cause the stack to be smashed, memory corruption and possibly code execution.

suse-cvrf
больше 4 лет назад

Security update for gstreamer, gstreamer-plugins-bad, gstreamer-plugins-base, gstreamer-plugins-good, gstreamer-plugins-ugly

suse-cvrf
больше 4 лет назад

Security update for gstreamer-plugins-bad