First published: Wed Apr 28 2021(Updated: )
GStreamer before 1.18.4 might do an out-of-bounds read when handling certain ID3v2 tags. Reference: <a href="https://gstreamer.freedesktop.org/security/sa-2021-0001.html">https://gstreamer.freedesktop.org/security/sa-2021-0001.html</a>
Affected Software | Affected Version | How to fix |
---|---|---|
GStreamer | <1.18.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1954761 is considered to be high due to the potential for out-of-bounds read vulnerabilities.
To fix REDHAT-BUG-1954761, upgrade GStreamer to version 1.18.4 or later.
REDHAT-BUG-1954761 is caused by GStreamer handling certain ID3v2 tags in a way that can result in out-of-bounds reads.
Versions of GStreamer prior to 1.18.4 are affected by REDHAT-BUG-1954761.
Currently, the recommended solution for REDHAT-BUG-1954761 is to upgrade to a fixed version rather than using a workaround.