CVE-2021-3185 - log back

CVE-2021-3185 edited at 26 Jan 2021 09:26:32
Description
- A flaw was found in the gstreamer h264 component where when parsing a h264 header, an attacker could cause the stack to be smashed, memory corruption and possibly code execution.
+ A flaw was found in the gstreamer h264 component of gst-plugins-bad before version 1.18.1 where when parsing a h264 header, an attacker could cause the stack to be smashed, leading to memory corruption and possibly code execution.
CVE-2021-3185 edited at 21 Jan 2021 09:28:11
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1917192
+ https://www.openwall.com/lists/oss-security/2021/01/20/1
https://gitlab.freedesktop.org/gstreamer/gst-plugins-bad/-/merge_requests/1703
https://gitlab.freedesktop.org/gstreamer/gst-plugins-bad/-/commit/bd3532008f2a12377c2d5b56e93cbfa53e1979cf
CVE-2021-3185 edited at 20 Jan 2021 17:34:34
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Local
Type
- Unknown
+ Arbitrary code execution
Description
+ A flaw was found in the gstreamer h264 component where when parsing a h264 header, an attacker could cause the stack to be smashed, memory corruption and possibly code execution.
References
+ https://bugzilla.redhat.com/show_bug.cgi?id=1917192
+ https://gitlab.freedesktop.org/gstreamer/gst-plugins-bad/-/merge_requests/1703
+ https://gitlab.freedesktop.org/gstreamer/gst-plugins-bad/-/commit/bd3532008f2a12377c2d5b56e93cbfa53e1979cf
Notes
CVE-2021-3185 created at 20 Jan 2021 17:32:44