CVE-2021-3498: Buffer Overflow
GStreamer before 1.18.4 might cause heap corruption when parsing certain malformed Matroska files.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/gst-plugins-good1.0to a version that resolves this vulnerability.Fixed in 1.14.4-1+deb10u1Fixed in 1.14.4-1+deb10u3Fixed in 1.18.4-2+deb11u2Fixed in 1.22.0-5+deb12u1Fixed in 1.22.6-1 - Upgrade
Upgrade
redhat/gstreamer-plugins-goodto a version that resolves this vulnerability.Fixed in 1.18.4 - Upgrade
Upgrade
gstreamerto a version that resolves this vulnerability.Fixed in 1.18.4Patch sa-2021-0003
Event History
Frequently Asked Questions
What is CVE-2021-3498?
CVE-2021-3498 is a vulnerability in GStreamer before version 1.18.4 that can cause heap corruption when parsing certain malformed Matroska files.
How does CVE-2021-3498 affect GStreamer?
CVE-2021-3498 affects GStreamer versions before 1.18.4 and can cause heap corruption when parsing certain malformed Matroska files.
What is the severity of CVE-2021-3498?
CVE-2021-3498 has a severity rating of 7.8 (high).
How can I fix CVE-2021-3498 in GStreamer?
To fix CVE-2021-3498 in GStreamer, update to version 1.18.4 or later.
Where can I find more information about CVE-2021-3498?
You can find more information about CVE-2021-3498 on the following references: http://packetstormsecurity.com/files/162952/Gstreamer-Matroska-Demuxing-Use-After-Free.html, https://bugzilla.redhat.com/show_bug.cgi?id=1945342, https://gstreamer.freedesktop.org/security/sa-2021-0003.html