CVE-2021-3185

NameCVE-2021-3185
DescriptionA flaw was found in the gstreamer h264 component of gst-plugins-bad before v1.18.1 where when parsing a h264 header, an attacker could cause the stack to be smashed, memory corruption and possibly code execution.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-2528-1, DSA-4833-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
gst-plugins-bad1.0 (PTS)buster1.14.4-1+deb10u2fixed
buster (security)1.14.4-1+deb10u5fixed
bullseye (security), bullseye1.18.4-3+deb11u4fixed
bookworm, bookworm (security)1.22.0-4+deb12u5fixed
trixie1.22.10-1fixed
sid1.24.1-4fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
gst-plugins-bad1.0sourcestretch1.10.4-1+deb9u1DLA-2528-1
gst-plugins-bad1.0sourcebuster1.14.4-1deb10u1DSA-4833-1
gst-plugins-bad1.0source(unstable)1.18.1-1

Notes

https://bugzilla.redhat.com/show_bug.cgi?id=1917192
https://gitlab.freedesktop.org/gstreamer/gst-plugins-bad/-/commit/11353b3f6e2f047cc37483d21e6a37ae558896bc
https://www.openwall.com/lists/oss-security/2021/01/20/1

Search for package or bug name: Reporting problems