[Git][security-tracker-team/security-tracker][master] CVE-2021-3498/gst-plugins-good1.0 n/a on stretch
Emilio Pozuelo Monfort
pochu at debian.org
Fri Apr 23 10:14:34 BST 2021
Emilio Pozuelo Monfort pushed to branch master at Debian Security Tracker / security-tracker
Commits:
381d2632 by Emilio Pozuelo Monfort at 2021-04-23T11:14:02+02:00
CVE-2021-3498/gst-plugins-good1.0 n/a on stretch
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -2058,13 +2058,15 @@ CVE-2021-XXXX [stack corruption when handling files with more than 64 audio chan
CVE-2021-3498 (GStreamer before 1.18.4 might cause heap corruption when parsing certa ...)
[experimental] - gst-plugins-good1.0 1.18.4-1
- gst-plugins-good1.0 1.18.4-2 (bug #986911)
+ [stretch] - gst-plugins-good1.0 <not-affected> (Vulnerable code introduced later)
NOTE: https://gstreamer.freedesktop.org/security/sa-2021-0003.html
- NOTE: https://gitlab.freedesktop.org/gstreamer/gst-plugins-good/-/commit/02174790726dd20a5c73ce2002189bf240ad4fe0?merge_request_iid=903
+ NOTE: https://gitlab.freedesktop.org/gstreamer/gst-plugins-good/-/commit/02174790726dd20a5c73ce2002189bf240ad4fe0
+ NOTE: Introduced by: https://gitlab.freedesktop.org/gstreamer/gst-plugins-good/-/commit/f279bc5336dda19741a5996a108da42dd3201366
CVE-2021-3497 (GStreamer before 1.18.4 might access already-freed memory in error cod ...)
[experimental] - gst-plugins-good1.0 1.18.4-1
- gst-plugins-good1.0 1.18.4-2 (bug #986910)
NOTE: https://gstreamer.freedesktop.org/security/sa-2021-0002.html
- NOTE: https://gitlab.freedesktop.org/gstreamer/gst-plugins-good/-/commit/9181191511f9c0be6a89c98b311f49d66bd46dc3?merge_request_iid=903
+ NOTE: https://gitlab.freedesktop.org/gstreamer/gst-plugins-good/-/commit/9181191511f9c0be6a89c98b311f49d66bd46dc3
CVE-2021-3496 (A heap-based buffer overflow was found in jhead in version 3.06 in Get ...)
- jhead <unfixed> (bug #986923; unimportant)
NOTE: https://github.com/Matthias-Wandel/jhead/issues/33
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/381d2632015d83571dec288799a498797b777973
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/381d2632015d83571dec288799a498797b777973
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210423/17771021/attachment.htm>
More information about the debian-security-tracker-commits
mailing list