6.8
CVSSv2

CVE-2021-3497

Published: 19/04/2021 Updated: 28/09/2022
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

GStreamer prior to 1.18.4 might access already-freed memory in error code paths when demuxing certain malformed Matroska files.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gstreamer project gstreamer

redhat enterprise linux 7.0

debian debian linux 9.0

debian debian linux 10.0

redhat enterprise linux 8.0

Vendor Advisories

Debian Bug report logs - #986910 gst-plugins-good10: CVE-2021-3497 Package: src:gst-plugins-good10; Maintainer for src:gst-plugins-good10 is Maintainers of GStreamer packages <gst-plugins-good10@packagesdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 14 Apr 2021 06:45:02 UTC Severit ...
Multiple vulnerabilities were discovered in plugins for the GStreamer media framework, which may result in denial of service or potentially the execution of arbitrary code if a malformed media file is opened For the stable distribution (buster), these problems have been fixed in version 1144-1+deb10u1 We recommend that you upgrade your gst-plug ...
GStreamer before 1184 might access already-freed memory in error code paths when demuxing certain malformed Matroska files (CVE-2021-3497) ...
No description is available for this CVE ...