PT-2021-7908 · Libaom+4 · Libaom+4

Published

2021-05-06

·

Updated

2024-01-31

·

CVE-2021-30473

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libaom versions prior to 2021-04-07
Description The issue is related to the incorrect handling of memory in the aom image.c component of the libaom library, which implements the AV1 codec. This can potentially allow a remote attacker to execute arbitrary code. The problem is caused by the freeing of memory that is not located on the heap.
Recommendations For versions prior to 2021-04-07, update to a version released after 2021-04-07 to resolve the issue. As a temporary workaround, consider restricting access to the aom image.c component until a patch is available.

Fix

Weakness Enumeration

Related Identifiers

BDU:2023-05295
CVE-2021-30473
DLA-3556-1
DSA-5490-1
MGASA-2021-0352
OPENSUSE-SU-2022_1436-1
SUSE-SU-2022:1436-1
SUSE-SU-2022_1436-1
USN-6447-1

Affected Products

Astra Linux
Linuxmint
Suse
Ubuntu
Libaom