VDB
GCVE-110-MAGEIA-2021-187
GCVE-110-MAGEIA-2021-187
Advisory Published
GStreamer before 1.18.4 might access already-freed memory in error code
paths when demuxing certain malformed Matroska files (SA-2021-0002).
GStreamer before 1.18.4 might cause heap corruption when parsing certain
malformed Matroska files (SA-2021-0003).
GStreamer before 1.18.4 might do an out-of-bounds read when handling
certain RealMedia files or streams (SA-2021-0004).
GStreamer before 1.18.4 might cause stack corruptions with streams that
have more than 64 audio channels (SA-2021-0005).
It might be possible for a malicious third party to trigger a crash in
the application, but possibly also an arbitrary code execution with the
privileges of the target user.
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | gstreamer1.0-plugins-ugly | 0 (affected), 1.16.0-1.1.mga7 (unaffected), 1.16.0-1.1.mga7.tainted (unaffected), 0 (affected), 1.16.0-1.1.mga7 (unaffected), 0 (affected), 1.16.0-1.1.mga7.tainted (unaffected), 0 (affected) | — |
| Mageia | gstreamer1.0-libav | 0 (affected), 1.18.3-1.1.mga8 (unaffected), 1.18.3-1.1.mga8 (unaffected), 0 (affected) | — |
| Mageia | gstreamer1.0-libav | 0 (affected), 1.16.0-1.1.mga7 (unaffected), 0 (affected), 1.16.0-1.1.mga7 (unaffected) | — |
| Mageia | gstreamer1.0-plugins-ugly | 0 (affected), 1.18.3-1.1.mga8 (unaffected), 0 (affected), 1.18.3-1.1.mga8.tainted (unaffected), 0 (affected), 0 (affected), 1.18.3-1.1.mga8.tainted (unaffected), 1.18.3-1.1.mga8 (unaffected) | — |
| Mageia | gstreamer1.0-plugins-good | 0 (affected), 1.18.3-1.2.mga8 (unaffected), 1.18.3-1.2.mga8 (unaffected), 0 (affected) | — |
| Mageia | gstreamer1.0-plugins-good | 0 (affected), 1.16.0-1.1.mga7 (unaffected), 0 (affected), 1.16.0-1.1.mga7 (unaffected) | — |
| Mageia | fvwm3 | 0 (affected), 1.0.2-1.1.mga8 (unaffected) | — |
References
Browse GCVE Records
75,823 records in the GCVE database · Updated August 3, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.