CVE-2021-3522: Medium severity Gstreamer Project Gstreamer vulnerability
GStreamer before 1.18.4 may perform an out-of-bounds read when handling certain ID3v2 tags.
Other sources
GStreamer before 1.18.4 might do an out-of-bounds read when handling certain ID3v2 tags.
Reference: https://gstreamer.freedesktop.org/security/sa-2021-0001.html
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-3522?
CVE-2021-3522 is a vulnerability in GStreamer before 1.18.4 that may perform an out-of-bounds read when handling certain ID3v2 tags.
How severe is CVE-2021-3522?
CVE-2021-3522 has a severity level of 5.5 (medium).
Which software versions are affected by CVE-2021-3522?
GStreamer versions up to (but not including) 1.18.4 are affected by CVE-2021-3522.
How can I fix CVE-2021-3522?
To fix CVE-2021-3522, update GStreamer to version 1.18.4 or later.
Where can I find more information about CVE-2021-3522?
You can find more information about CVE-2021-3522 at the following references: [1](https://bugzilla.redhat.com/show_bug.cgi?id=1954761), [2](https://security.gentoo.org/glsa/202208-31), [3](https://security.netapp.com/advisory/ntap-20211022-0004/).