First published: Wed Apr 28 2021(Updated: )
GStreamer before 1.18.4 may perform an out-of-bounds read when handling certain ID3v2 tags.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Gstreamer Project Gstreamer | <1.18.4 | |
Netapp Active Iq Unified Manager Vmware Vsphere | ||
Netapp Active Iq Unified Manager Windows | ||
NetApp E-Series SANtricity OS Controller | >=11.0.0<=11.70.1 | |
Netapp E-series Santricity Storage Manager | ||
Netapp E-series Santricity Web Services Web Services Proxy | ||
Netapp Hci Management Node | ||
NetApp OnCommand Insight | ||
NetApp OnCommand Workflow Automation | ||
Netapp Santricity Unified Manager | ||
Netapp Snapmanager Oracle | ||
Netapp Snapmanager Sap | ||
Netapp Solidfire | ||
Oracle OpenJDK | =8-update301 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-3522 is a vulnerability in GStreamer before 1.18.4 that may perform an out-of-bounds read when handling certain ID3v2 tags.
CVE-2021-3522 has a severity level of 5.5 (medium).
GStreamer versions up to (but not including) 1.18.4 are affected by CVE-2021-3522.
To fix CVE-2021-3522, update GStreamer to version 1.18.4 or later.
You can find more information about CVE-2021-3522 at the following references: [1](https://bugzilla.redhat.com/show_bug.cgi?id=1954761), [2](https://security.gentoo.org/glsa/202208-31), [3](https://security.netapp.com/advisory/ntap-20211022-0004/).