First published: Wed Apr 28 2021(Updated: )
GStreamer before 1.18.4 may perform an out-of-bounds read when handling certain ID3v2 tags.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
GStreamer | <1.18.4 | |
NetApp Active IQ Unified Manager for VMware vSphere | ||
NetApp Active IQ Unified Manager | ||
NetApp E-Series SANtricity OS Controller | >=11.0.0<=11.70.1 | |
NetApp SANtricity Storage Manager | ||
NetApp E-Series SANtricity Web Services | ||
NetApp SolidFire & HCI Management Node | ||
NetApp OnCommand Insight | ||
NetApp OnCommand Workflow Automation | ||
NetApp E-Series SANtricity Unified Manager | ||
NetApp SnapManager for Oracle | ||
NetApp SnapManager for SAP | ||
NetApp SolidFire & HCI Storage Node | ||
OpenJDK 8 | =8-update301 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-3522 is a vulnerability in GStreamer before 1.18.4 that may perform an out-of-bounds read when handling certain ID3v2 tags.
CVE-2021-3522 has a severity level of 5.5 (medium).
GStreamer versions up to (but not including) 1.18.4 are affected by CVE-2021-3522.
To fix CVE-2021-3522, update GStreamer to version 1.18.4 or later.
You can find more information about CVE-2021-3522 at the following references: [1](https://bugzilla.redhat.com/show_bug.cgi?id=1954761), [2](https://security.gentoo.org/glsa/202208-31), [3](https://security.netapp.com/advisory/ntap-20211022-0004/).