First published: Mon Jan 18 2021(Updated: )
A flaw was found in the gstreamer h264 component of gst-plugins-bad before v1.18.1 where when parsing a h264 header, an attacker could cause the stack to be smashed, memory corruption and possibly code execution.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/gst-plugins-bad | <1.18.1 | 1.18.1 |
Freedesktop Gst-plugins-bad | <1.18.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-3185 is a vulnerability found in the gstreamer h264 component of gst-plugins-bad before v1.18.1.
The impact of CVE-2021-3185 is stack smashing, memory corruption, and possible code execution.
The software affected by CVE-2021-3185 includes gst-plugins-bad before v1.18.1 from Red Hat and Gst-plugins-bad from the Freedesktop project.
The severity of CVE-2021-3185 is critical with a CVSS score of 9.8.
To fix CVE-2021-3185, update gst-plugins-bad to version 1.18.1 or newer.