First published: Wed Jun 02 2021(Updated: )
aom_dsp/grain_table.c in libaom in AOMedia before 2021-03-30 has a use-after-free.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Aomedia Aomedia | <2021-03-30 | |
ubuntu/aom | <1.0.0. | 1.0.0. |
ubuntu/aom | <3.2.0-1 | 3.2.0-1 |
debian/aom | 1.0.0.errata1-3+deb11u1 3.6.0-1 3.9.1-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-30474 is a use-after-free vulnerability in libaom, allowing an attacker to execute arbitrary code or cause a denial of service.
CVE-2021-30474 has a severity rating of 9.8 (Critical).
Aomedia Aomedia versions up to and excluding 2021-03-30, and the debian/aom package versions 1.0.0-3, 1.0.0.errata1-3, 3.6.0-1, and 3.7.0~really3.6.1-1 are affected by CVE-2021-30474.
To fix CVE-2021-30474, update to a version of Aomedia Aomedia after 2021-03-30 or debian/aom package versions 1.0.0-3+, 1.0.0.errata1-3+, 3.6.0-1, or 3.7.0~really3.6.1-1.
More information about CVE-2021-30474 can be found at the following references: - https://aomedia.googlesource.com/aom/+/6e31957b6dc62dbc7d1bb70cd84902dd14c4bf2e - https://bugs.chromium.org/p/aomedia/issues/detail?id=3000 - https://lists.debian.org/debian-lts-announce/2023/09/msg00003.html