First published: Wed Apr 28 2021(Updated: )
GStreamer before 1.18.4 may perform an out-of-bounds read when handling certain ID3v2 tags.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
GStreamer | <1.18.4 | |
NetApp Active IQ Unified Manager for VMware vSphere | ||
netapp active iq unified manager windows | ||
NetApp E-Series SANtricity OS Controller | >=11.0.0<=11.70.1 | |
netapp e-series santricity storage manager | ||
netapp e-series santricity Web services Web services proxy | ||
netapp hci management node | ||
NetApp OnCommand Insight | ||
NetApp OnCommand Workflow Automation | ||
netapp santricity unified manager | ||
netapp snapmanager Oracle | ||
netapp snapmanager sap | ||
netapp solidfire | ||
OpenJDK 17 | =8-update301 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-3522 is a vulnerability in GStreamer before 1.18.4 that may perform an out-of-bounds read when handling certain ID3v2 tags.
CVE-2021-3522 has a severity level of 5.5 (medium).
GStreamer versions up to (but not including) 1.18.4 are affected by CVE-2021-3522.
To fix CVE-2021-3522, update GStreamer to version 1.18.4 or later.
You can find more information about CVE-2021-3522 at the following references: [1](https://bugzilla.redhat.com/show_bug.cgi?id=1954761), [2](https://security.gentoo.org/glsa/202208-31), [3](https://security.netapp.com/advisory/ntap-20211022-0004/).