PT-2021-7907 · Libaom+4 · Libaom+4

Published

2021-06-04

·

Updated

2024-06-15

·

CVE-2021-30475

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libaom versions prior to 2021-03-24
Description The issue is caused by a buffer overflow in the aom dsp/noise model.c component of the libaom library, which implements the AV1 codec. This can allow a remote attacker to execute arbitrary code.
Recommendations For versions prior to 2021-03-24, update to a version released after 2021-03-24 to resolve the issue. As a temporary workaround, consider restricting access to the aom dsp/noise model.c component until a patch is available.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-05294
CVE-2021-30475
DLA-3556-1
DSA-5490-1
MGASA-2021-0352
OPENSUSE-SU-2021:1254-1
OPENSUSE-SU-2021:3005-1
OPENSUSE-SU-2021_1254-1
OPENSUSE-SU-2021_3005-1
OPENSUSE-SU-2024:10924-1
SUSE-SU-2021:3005-1
SUSE-SU-2021_3005-1
USN-6447-1

Affected Products

Astra Linux
Linuxmint
Suse
Ubuntu
Libaom