{"cves":[{"id":"CVE-2021-3498","published":"2021-04-19T21:15:00","updated_at":"2025-08-25T23:37:51.328146+00:00","description":"\nGStreamer before 1.18.4 might cause heap corruption when parsing certain\nmalformed Matroska files.","ubuntu_description":"","notes":[{"author":"leosilva","note":"xenial does not uses affected variable/code dest_context."}],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://gstreamer.freedesktop.org/security/sa-2021-0003.html","https://gitlab.freedesktop.org/gstreamer/gst-plugins-good/-/commit/02174790726dd20a5c73ce2002189bf240ad4fe0?merge_request_iid=903","https://ubuntu.com/security/notices/USN-4928-1","https://www.cve.org/CVERecord?id=CVE-2021-3498"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=986911"],"patches":{"gst-plugins-good1.0":[]},"tags":{},"packages":[{"name":"gst-plugins-good1.0","source":"https://ubuntu.com/security/cve?package=gst-plugins-good1.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gst-plugins-good1.0","debian":"https://tracker.debian.org/pkg/gst-plugins-good1.0","statuses":[{"release_codename":"hirsute","status":"not-affected","description":"1.18.4-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.14.5-0ubuntu1~18.04.2","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1.16.2-1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"released","description":"1.18.0-1ubuntu1.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-4928-1"],"notices":[{"id":"USN-4928-1","title":"GStreamer Good Plugins vulnerabilities","summary":"Several security issues were fixed in GStreamer Plugins Good.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-04-28T17:15:06.289013","description":"It was discovered that GStreamer Good Plugins incorrectly handled certain files.\nAn attacker could possibly use this issue to cause access sensitive information\nor cause a crash. (CVE-2021-3497)\n\nIt was discovered that GStreamer Good Plugins incorrectly handled certain files.\nAn attacker could possibly use this issue to execute arbitrary code or cause\na crash. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu\n20.10. (CVE-2021-3498)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"gst-plugins-good1.0","version":"1.14.5-0ubuntu1~18.04.2","description":"GStreamer plugins","is_source":true},{"name":"gstreamer1.0-gtk3","version":"1.14.5-0ubuntu1~18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.14.5-0ubuntu1~18.04.2","pocket":"security"},{"name":"gstreamer1.0-plugins-good","version":"1.14.5-0ubuntu1~18.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.14.5-0ubuntu1~18.04.2","pocket":"security"},{"name":"gstreamer1.0-plugins-good-doc","version":"1.14.5-0ubuntu1~18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.14.5-0ubuntu1~18.04.2","pocket":"security"},{"name":"gstreamer1.0-pulseaudio","version":"1.14.5-0ubuntu1~18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.14.5-0ubuntu1~18.04.2","pocket":"security"},{"name":"gstreamer1.0-qt5","version":"1.14.5-0ubuntu1~18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.14.5-0ubuntu1~18.04.2","pocket":"security"},{"name":"libgstreamer-plugins-good1.0-0","version":"1.14.5-0ubuntu1~18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.14.5-0ubuntu1~18.04.2","pocket":"security"},{"name":"libgstreamer-plugins-good1.0-dev","version":"1.14.5-0ubuntu1~18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.14.5-0ubuntu1~18.04.2","pocket":"security"}],"focal":[{"name":"gst-plugins-good1.0","version":"1.16.2-1ubuntu2.1","description":"GStreamer plugins","is_source":true},{"name":"gstreamer1.0-gtk3","version":"1.16.2-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.16.2-1ubuntu2.1","pocket":"security"},{"name":"gstreamer1.0-plugins-good","version":"1.16.2-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.16.2-1ubuntu2.1","pocket":"security"},{"name":"gstreamer1.0-plugins-good-doc","version":"1.16.2-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.16.2-1ubuntu2.1","pocket":"security"},{"name":"gstreamer1.0-pulseaudio","version":"1.16.2-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.16.2-1ubuntu2.1","pocket":"security"},{"name":"gstreamer1.0-qt5","version":"1.16.2-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.16.2-1ubuntu2.1","pocket":"security"},{"name":"libgstreamer-plugins-good1.0-0","version":"1.16.2-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.16.2-1ubuntu2.1","pocket":"security"},{"name":"libgstreamer-plugins-good1.0-dev","version":"1.16.2-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.16.2-1ubuntu2.1","pocket":"security"}],"groovy":[{"name":"gst-plugins-good1.0","version":"1.18.0-1ubuntu1.1","description":"GStreamer plugins","is_source":true},{"name":"gstreamer1.0-gtk3","version":"1.18.0-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.18.0-1ubuntu1.1","pocket":"security"},{"name":"gstreamer1.0-plugins-good","version":"1.18.0-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.18.0-1ubuntu1.1","pocket":"security"},{"name":"gstreamer1.0-pulseaudio","version":"1.18.0-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.18.0-1ubuntu1.1","pocket":"security"},{"name":"gstreamer1.0-qt5","version":"1.18.0-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.18.0-1ubuntu1.1","pocket":"security"},{"name":"libgstreamer-plugins-good1.0-0","version":"1.18.0-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.18.0-1ubuntu1.1","pocket":"security"},{"name":"libgstreamer-plugins-good1.0-dev","version":"1.18.0-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.18.0-1ubuntu1.1","pocket":"security"}],"xenial":[{"name":"gst-plugins-good1.0","version":"1.8.3-1ubuntu0.5","description":"GStreamer plugins","is_source":true},{"name":"gstreamer1.0-plugins-good","version":"1.8.3-1ubuntu0.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.8.3-1ubuntu0.5","pocket":"security"},{"name":"gstreamer1.0-plugins-good-doc","version":"1.8.3-1ubuntu0.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.8.3-1ubuntu0.5","pocket":"security"},{"name":"gstreamer1.0-pulseaudio","version":"1.8.3-1ubuntu0.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.8.3-1ubuntu0.5","pocket":"security"},{"name":"libgstreamer-plugins-good1.0-0","version":"1.8.3-1ubuntu0.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.8.3-1ubuntu0.5","pocket":"security"},{"name":"libgstreamer-plugins-good1.0-dev","version":"1.8.3-1ubuntu0.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.8.3-1ubuntu0.5","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2021-3498","CVE-2021-3497"]}]},{"id":"CVE-2021-3497","published":"2021-04-19T21:15:00","updated_at":"2025-08-25T23:37:51.328146+00:00","description":"\nGStreamer before 1.18.4 might access already-freed memory in error code\npaths when demuxing certain malformed Matroska files.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://gstreamer.freedesktop.org/security/sa-2021-0002.html","https://gitlab.freedesktop.org/gstreamer/gst-plugins-good/-/commit/9181191511f9c0be6a89c98b311f49d66bd46dc3?merge_request_iid=903","https://ubuntu.com/security/notices/USN-4928-1","https://www.cve.org/CVERecord?id=CVE-2021-3497"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=986910"],"patches":{"gst-plugins-good1.0":[]},"tags":{},"packages":[{"name":"gst-plugins-good1.0","source":"https://ubuntu.com/security/cve?package=gst-plugins-good1.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gst-plugins-good1.0","debian":"https://tracker.debian.org/pkg/gst-plugins-good1.0","statuses":[{"release_codename":"bionic","status":"released","description":"1.14.5-0ubuntu1~18.04.2","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"1.18.4-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1.16.2-1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"released","description":"1.18.0-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.8.3-1ubuntu0.5","component":null,"pocket":"security"}]}],"notices_ids":["USN-4928-1"],"notices":[{"id":"USN-4928-1","title":"GStreamer Good Plugins vulnerabilities","summary":"Several security issues were fixed in GStreamer Plugins Good.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-04-28T17:15:06.289013","description":"It was discovered that GStreamer Good Plugins incorrectly handled certain files.\nAn attacker could possibly use this issue to cause access sensitive information\nor cause a crash. (CVE-2021-3497)\n\nIt was discovered that GStreamer Good Plugins incorrectly handled certain files.\nAn attacker could possibly use this issue to execute arbitrary code or cause\na crash. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu\n20.10. (CVE-2021-3498)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"gst-plugins-good1.0","version":"1.14.5-0ubuntu1~18.04.2","description":"GStreamer plugins","is_source":true},{"name":"gstreamer1.0-gtk3","version":"1.14.5-0ubuntu1~18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.14.5-0ubuntu1~18.04.2","pocket":"security"},{"name":"gstreamer1.0-plugins-good","version":"1.14.5-0ubuntu1~18.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.14.5-0ubuntu1~18.04.2","pocket":"security"},{"name":"gstreamer1.0-plugins-good-doc","version":"1.14.5-0ubuntu1~18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.14.5-0ubuntu1~18.04.2","pocket":"security"},{"name":"gstreamer1.0-pulseaudio","version":"1.14.5-0ubuntu1~18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.14.5-0ubuntu1~18.04.2","pocket":"security"},{"name":"gstreamer1.0-qt5","version":"1.14.5-0ubuntu1~18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.14.5-0ubuntu1~18.04.2","pocket":"security"},{"name":"libgstreamer-plugins-good1.0-0","version":"1.14.5-0ubuntu1~18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.14.5-0ubuntu1~18.04.2","pocket":"security"},{"name":"libgstreamer-plugins-good1.0-dev","version":"1.14.5-0ubuntu1~18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.14.5-0ubuntu1~18.04.2","pocket":"security"}],"focal":[{"name":"gst-plugins-good1.0","version":"1.16.2-1ubuntu2.1","description":"GStreamer plugins","is_source":true},{"name":"gstreamer1.0-gtk3","version":"1.16.2-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.16.2-1ubuntu2.1","pocket":"security"},{"name":"gstreamer1.0-plugins-good","version":"1.16.2-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.16.2-1ubuntu2.1","pocket":"security"},{"name":"gstreamer1.0-plugins-good-doc","version":"1.16.2-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.16.2-1ubuntu2.1","pocket":"security"},{"name":"gstreamer1.0-pulseaudio","version":"1.16.2-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.16.2-1ubuntu2.1","pocket":"security"},{"name":"gstreamer1.0-qt5","version":"1.16.2-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.16.2-1ubuntu2.1","pocket":"security"},{"name":"libgstreamer-plugins-good1.0-0","version":"1.16.2-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.16.2-1ubuntu2.1","pocket":"security"},{"name":"libgstreamer-plugins-good1.0-dev","version":"1.16.2-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.16.2-1ubuntu2.1","pocket":"security"}],"groovy":[{"name":"gst-plugins-good1.0","version":"1.18.0-1ubuntu1.1","description":"GStreamer plugins","is_source":true},{"name":"gstreamer1.0-gtk3","version":"1.18.0-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.18.0-1ubuntu1.1","pocket":"security"},{"name":"gstreamer1.0-plugins-good","version":"1.18.0-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.18.0-1ubuntu1.1","pocket":"security"},{"name":"gstreamer1.0-pulseaudio","version":"1.18.0-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.18.0-1ubuntu1.1","pocket":"security"},{"name":"gstreamer1.0-qt5","version":"1.18.0-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.18.0-1ubuntu1.1","pocket":"security"},{"name":"libgstreamer-plugins-good1.0-0","version":"1.18.0-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.18.0-1ubuntu1.1","pocket":"security"},{"name":"libgstreamer-plugins-good1.0-dev","version":"1.18.0-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.18.0-1ubuntu1.1","pocket":"security"}],"xenial":[{"name":"gst-plugins-good1.0","version":"1.8.3-1ubuntu0.5","description":"GStreamer plugins","is_source":true},{"name":"gstreamer1.0-plugins-good","version":"1.8.3-1ubuntu0.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.8.3-1ubuntu0.5","pocket":"security"},{"name":"gstreamer1.0-plugins-good-doc","version":"1.8.3-1ubuntu0.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.8.3-1ubuntu0.5","pocket":"security"},{"name":"gstreamer1.0-pulseaudio","version":"1.8.3-1ubuntu0.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.8.3-1ubuntu0.5","pocket":"security"},{"name":"libgstreamer-plugins-good1.0-0","version":"1.8.3-1ubuntu0.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.8.3-1ubuntu0.5","pocket":"security"},{"name":"libgstreamer-plugins-good1.0-dev","version":"1.8.3-1ubuntu0.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.8.3-1ubuntu0.5","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2021-3498","CVE-2021-3497"]}]},{"id":"CVE-2021-30199","published":"2021-04-19T20:15:00","updated_at":"2025-08-26T12:30:59.436824+00:00","description":"\nIn filters/reframe_latm.c in GPAC 1.0.1 there is a Null Pointer\nDereference, when gf_filter_pck_get_data is called. The first arg pck may\nbe null with a crafted mp4 file,which results in a crash.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/gpac/gpac/commit/b2db2f99b4c30f96e17b9a14537c776da6cb5dca","https://github.com/gpac/gpac/issues/1728","https://www.cve.org/CVERecord?id=CVE-2021-30199"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=987323"],"patches":{"gpac":[]},"tags":{},"packages":[{"name":"gpac","source":"https://ubuntu.com/security/cve?package=gpac","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gpac","debian":"https://tracker.debian.org/pkg/gpac","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-30022","published":"2021-04-19T20:15:00","updated_at":"2025-08-04T18:13:35.741288+00:00","description":"\nThere is a integer overflow in media_tools/av_parsers.c in the\ngf_avc_read_pps_bs_internal in GPAC from 0.5.2 to 1.0.1. pps_id may be a\nnegative number, so it will not return. However, avc->pps only has 255\nunit, so there is an overflow, which results a crash.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/gpac/gpac/commit/51cdb67ff7c5f1242ac58c5aa603ceaf1793b788","https://github.com/gpac/gpac/issues/1720","https://www.cve.org/CVERecord?id=CVE-2021-30022"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=987323"],"patches":{"gpac":[]},"tags":{},"packages":[{"name":"gpac","source":"https://ubuntu.com/security/cve?package=gpac","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gpac","debian":"https://tracker.debian.org/pkg/gpac","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-30020","published":"2021-04-19T20:15:00","updated_at":"2025-08-26T12:30:43.782450+00:00","description":"\nIn the function gf_hevc_read_pps_bs_internal function in\nmedia_tools/av_parsers.c in GPAC 1.0.1 there is a loop, which with crafted\nfile, pps->num_tile_columns may be larger than sizeof(pps->column_width),\nwhich results in a heap overflow in the loop.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/gpac/gpac/commit/51cdb67ff7c5f1242ac58c5aa603ceaf1793b788","https://github.com/gpac/gpac/issues/1722","https://www.cve.org/CVERecord?id=CVE-2021-30020"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=987323"],"patches":{"gpac":[]},"tags":{},"packages":[{"name":"gpac","source":"https://ubuntu.com/security/cve?package=gpac","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gpac","debian":"https://tracker.debian.org/pkg/gpac","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-30019","published":"2021-04-19T20:15:00","updated_at":"2025-08-26T12:30:43.782450+00:00","description":"\nIn the adts_dmx_process function in filters/reframe_adts.c in GPAC 1.0.1, a\ncrafted file may cause ctx->hdr.frame_size to be smaller than\nctx->hdr.hdr_size, resulting in size to be a negative number and a heap\noverflow in the memcpy.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/gpac/gpac/commit/22774aa9e62f586319c8f107f5bae950fed900bc","https://github.com/gpac/gpac/issues/1723","https://www.cve.org/CVERecord?id=CVE-2021-30019"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=987323"],"patches":{"gpac":[]},"tags":{},"packages":[{"name":"gpac","source":"https://ubuntu.com/security/cve?package=gpac","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gpac","debian":"https://tracker.debian.org/pkg/gpac","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-30015","published":"2021-04-19T20:15:00","updated_at":"2025-08-26T12:30:43.782450+00:00","description":"\nThere is a Null Pointer Dereference in function\nfilter_core/filter_pck.c:gf_filter_pck_new_alloc_internal in GPAC 1.0.1.\nThe pid comes from function av1dmx_parse_flush_sample, the ctx.opid maybe\nNULL. The result is a crash in gf_filter_pck_new_alloc_internal.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/gpac/gpac/commit/13dad7d5ef74ca2e6fe4010f5b03eb12e9bbe0ec","https://github.com/gpac/gpac/issues/1719","https://www.cve.org/CVERecord?id=CVE-2021-30015"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=987323"],"patches":{"gpac":[]},"tags":{},"packages":[{"name":"gpac","source":"https://ubuntu.com/security/cve?package=gpac","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gpac","debian":"https://tracker.debian.org/pkg/gpac","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-30014","published":"2021-04-19T20:15:00","updated_at":"2025-08-04T18:13:35.741288+00:00","description":"\nThere is a integer overflow in media_tools/av_parsers.c in the\nhevc_parse_slice_segment function in GPAC from v0.9.0-preview to 1.0.1\nwhich results in a crash.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/gpac/gpac/commit/51cdb67ff7c5f1242ac58c5aa603ceaf1793b788","https://github.com/gpac/gpac/issues/1721","https://www.cve.org/CVERecord?id=CVE-2021-30014"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=987323"],"patches":{"gpac":[]},"tags":{},"packages":[{"name":"gpac","source":"https://ubuntu.com/security/cve?package=gpac","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gpac","debian":"https://tracker.debian.org/pkg/gpac","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-29279","published":"2021-04-19T20:15:00","updated_at":"2025-08-26T12:30:43.782450+00:00","description":"\nThere is a integer overflow in function\nfilter_core/filter_props.c:gf_props_assign_value in GPAC 1.0.1. In which,\nthe arg const GF_PropertyValue *value,maybe value->value.data.size is a\nnegative number. In result, memcpy in gf_props_assign_value failed.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/gpac/gpac/commit/da69ad1f970a7e17c865eaec9af98cc84df10d5b","https://github.com/gpac/gpac/issues/1718","https://www.cve.org/CVERecord?id=CVE-2021-29279"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=987323"],"patches":{"gpac":[]},"tags":{},"packages":[{"name":"gpac","source":"https://ubuntu.com/security/cve?package=gpac","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gpac","debian":"https://tracker.debian.org/pkg/gpac","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-31262","published":"2021-04-19T19:15:00","updated_at":"2025-08-26T12:30:59.436824+00:00","description":"\nThe AV1_DuplicateConfig function in GPAC 1.0.1 allows attackers to cause a\ndenial of service (NULL pointer dereference) via a crafted file in the\nMP4Box command.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/gpac/gpac/commit/b2eab95e07cb5819375a50358d4806a8813b6e50","https://github.com/gpac/gpac/issues/1738","https://www.cve.org/CVERecord?id=CVE-2021-31262"],"bugs":[""],"patches":{"gpac":[]},"tags":{},"packages":[{"name":"gpac","source":"https://ubuntu.com/security/cve?package=gpac","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gpac","debian":"https://tracker.debian.org/pkg/gpac","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-31261","published":"2021-04-19T19:15:00","updated_at":"2025-08-26T12:30:59.436824+00:00","description":"\nThe gf_hinter_track_new function in GPAC 1.0.1 allows attackers to read\nmemory via a crafted file in the MP4Box command.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/gpac/gpac/commit/cd3738dea038dbd12e603ad48cd7373ae0440f65","https://github.com/gpac/gpac/issues/1737","https://www.cve.org/CVERecord?id=CVE-2021-31261"],"bugs":[""],"patches":{"gpac":[]},"tags":{},"packages":[{"name":"gpac","source":"https://ubuntu.com/security/cve?package=gpac","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gpac","debian":"https://tracker.debian.org/pkg/gpac","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-31260","published":"2021-04-19T19:15:00","updated_at":"2025-08-26T12:30:59.436824+00:00","description":"\nThe MergeTrack function in GPAC 1.0.1 allows attackers to cause a denial of\nservice (NULL pointer dereference) via a crafted file in the MP4Box\ncommand.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/gpac/gpac/commit/df8fffd839fe5ae9acd82d26fd48280a397411d9","https://github.com/gpac/gpac/issues/1736","https://www.cve.org/CVERecord?id=CVE-2021-31260"],"bugs":[""],"patches":{"gpac":[]},"tags":{},"packages":[{"name":"gpac","source":"https://ubuntu.com/security/cve?package=gpac","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gpac","debian":"https://tracker.debian.org/pkg/gpac","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-31259","published":"2021-04-19T19:15:00","updated_at":"2025-08-26T12:30:59.436824+00:00","description":"\nThe gf_isom_cenc_get_default_info_internal function in GPAC 1.0.1 allows\nattackers to cause a denial of service (NULL pointer dereference) via a\ncrafted file in the MP4Box command.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/gpac/gpac/commit/3b84ffcbacf144ce35650df958432f472b6483f8","https://github.com/gpac/gpac/issues/1735","https://www.cve.org/CVERecord?id=CVE-2021-31259"],"bugs":[""],"patches":{"gpac":[]},"tags":{},"packages":[{"name":"gpac","source":"https://ubuntu.com/security/cve?package=gpac","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gpac","debian":"https://tracker.debian.org/pkg/gpac","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-31258","published":"2021-04-19T19:15:00","updated_at":"2025-08-26T12:30:59.436824+00:00","description":"\nThe gf_isom_set_extraction_slc function in GPAC 1.0.1 allows attackers to\ncause a denial of service (NULL pointer dereference) via a crafted file in\nthe MP4Box command.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/gpac/gpac/commit/ebfa346eff05049718f7b80041093b4c5581c24e","https://github.com/gpac/gpac/issues/1706","https://www.cve.org/CVERecord?id=CVE-2021-31258"],"bugs":[""],"patches":{"gpac":[]},"tags":{},"packages":[{"name":"gpac","source":"https://ubuntu.com/security/cve?package=gpac","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gpac","debian":"https://tracker.debian.org/pkg/gpac","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-31257","published":"2021-04-19T19:15:00","updated_at":"2025-08-26T12:30:59.436824+00:00","description":"\nThe HintFile function in GPAC 1.0.1 allows attackers to cause a denial of\nservice (NULL pointer dereference) via a crafted file in the MP4Box\ncommand.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/gpac/gpac/commit/87afe070cd6866df7fe80f11b26ef75161de85e0","https://github.com/gpac/gpac/issues/1734","https://www.cve.org/CVERecord?id=CVE-2021-31257"],"bugs":[""],"patches":{"gpac":[]},"tags":{},"packages":[{"name":"gpac","source":"https://ubuntu.com/security/cve?package=gpac","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gpac","debian":"https://tracker.debian.org/pkg/gpac","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-31256","published":"2021-04-19T19:15:00","updated_at":"2025-08-26T12:30:59.436824+00:00","description":"\nMemory leak in the stbl_GetSampleInfos function in MP4Box in GPAC 1.0.1\nallows attackers to read memory via a crafted file.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/gpac/gpac/commit/2da2f68bffd51d89b1d272d22aa8cc023c1c066e","https://github.com/gpac/gpac/issues/1705","https://www.cve.org/CVERecord?id=CVE-2021-31256"],"bugs":[""],"patches":{"gpac":[]},"tags":{},"packages":[{"name":"gpac","source":"https://ubuntu.com/security/cve?package=gpac","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gpac","debian":"https://tracker.debian.org/pkg/gpac","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-31255","published":"2021-04-19T19:15:00","updated_at":"2025-08-26T12:30:59.436824+00:00","description":"\nBuffer overflow in the abst_box_read function in MP4Box in GPAC 1.0.1\nallows attackers to cause a denial of service or execute arbitrary code via\na crafted file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/gpac/gpac/commit/758135e91e623d7dfe7f6aaad7aeb3f791b7a4e5","https://github.com/gpac/gpac/issues/1733","https://www.cve.org/CVERecord?id=CVE-2021-31255"],"bugs":[""],"patches":{"gpac":[]},"tags":{},"packages":[{"name":"gpac","source":"https://ubuntu.com/security/cve?package=gpac","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gpac","debian":"https://tracker.debian.org/pkg/gpac","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-31254","published":"2021-04-19T19:15:00","updated_at":"2025-08-26T12:30:59.436824+00:00","description":"\nBuffer overflow in the tenc_box_read function in MP4Box in GPAC 1.0.1\nallows attackers to cause a denial of service or execute arbitrary code via\na crafted file, related invalid IV sizes.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/gpac/gpac/commit/8986422c21fbd9a7bf6561cae65aae42077447e8","https://github.com/gpac/gpac/issues/1703","https://www.cve.org/CVERecord?id=CVE-2021-31254"],"bugs":[""],"patches":{"gpac":[]},"tags":{},"packages":[{"name":"gpac","source":"https://ubuntu.com/security/cve?package=gpac","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gpac","debian":"https://tracker.debian.org/pkg/gpac","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-29458","published":"2021-04-19T19:15:00","updated_at":"2025-08-25T23:34:34.563621+00:00","description":"\nExiv2 is a command-line utility and C++ library for reading, writing,\ndeleting, and modifying the metadata of image files. An out-of-bounds read\nwas found in Exiv2 versions v0.27.3 and earlier. The out-of-bounds read is\ntriggered when Exiv2 is used to write metadata into a crafted image file.\nAn attacker could potentially exploit the vulnerability to cause a denial\nof service by crashing Exiv2, if they can trick the victim into running\nExiv2 on a crafted image file. Note that this bug is only triggered when\nwriting the metadata, which is a less frequently used Exiv2 operation than\nreading the metadata. For example, to trigger the bug in the Exiv2\ncommand-line application, you need to add an extra command-line argument\nsuch as insert. The bug is fixed in version v0.27.4.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/Exiv2/exiv2/security/advisories/GHSA-57jj-75fm-9rq5","https://github.com/Exiv2/exiv2/issues/1530","https://github.com/Exiv2/exiv2/pull/1536","https://ubuntu.com/security/notices/USN-4941-1","https://www.cve.org/CVERecord?id=CVE-2021-29458"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/exiv2/+bug/1923479"],"patches":{"exiv2":["upstream: https://github.com/Exiv2/exiv2/pull/1536/commits/9b7a19f957af53304655ed1efe32253a1b11a8d0"]},"tags":{},"packages":[{"name":"exiv2","source":"https://ubuntu.com/security/cve?package=exiv2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=exiv2","debian":"https://tracker.debian.org/pkg/exiv2","statuses":[{"release_codename":"bionic","status":"released","description":"0.25-3.1ubuntu0.18.04.7","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"0.27.2-8ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"groovy","status":"released","description":"0.27.3-3ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"0.27.3-3ubuntu2","component":null,"pocket":"security"},{"release_codename":"impish","status":"released","description":"0.27.3-3ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"released","description":"0.27.3-3ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.25-2.1ubuntu16.04.7+esm1","component":null,"pocket":"esm-infra"}]}],"notices_ids":["USN-4941-1"],"notices":[{"id":"USN-4941-1","title":"Exiv2 vulnerabilities","summary":"Several security issues were fixed in Exiv2.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-05-10T18:07:19.189006","description":"It was discovered that Exiv2 incorrectly handled certain images.\nAn attacker could possibly use this issue to execute arbitrary code or cause\na crash. (CVE-2021-29457)\n\nIt was discovered that Exiv2 incorrectly handled certain images.\nAn attacker could possibly use this issue to cause a denial of service.\n(CVE-2021-29458, CVE-2021-29470)\n\nIt was discovered that Exiv2 incorrectly handled certain images.\nAn attacker could possibly use this issue to execute arbitrary code or\ncause a crash. (CVE-2021-3482)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"exiv2","version":"0.25-3.1ubuntu0.18.04.7","description":"EXIF/IPTC/XMP metadata manipulation tool","is_source":true},{"name":"exiv2","version":"0.25-3.1ubuntu0.18.04.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.25-3.1ubuntu0.18.04.7","pocket":"security"},{"name":"libexiv2-14","version":"0.25-3.1ubuntu0.18.04.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.25-3.1ubuntu0.18.04.7","pocket":"security"},{"name":"libexiv2-dev","version":"0.25-3.1ubuntu0.18.04.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.25-3.1ubuntu0.18.04.7","pocket":"security"},{"name":"libexiv2-doc","version":"0.25-3.1ubuntu0.18.04.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.25-3.1ubuntu0.18.04.7","pocket":"security"}],"focal":[{"name":"exiv2","version":"0.27.2-8ubuntu2.2","description":"EXIF/IPTC/XMP metadata manipulation tool","is_source":true},{"name":"exiv2","version":"0.27.2-8ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.27.2-8ubuntu2.2","pocket":"security"},{"name":"libexiv2-27","version":"0.27.2-8ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.27.2-8ubuntu2.2","pocket":"security"},{"name":"libexiv2-dev","version":"0.27.2-8ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.27.2-8ubuntu2.2","pocket":"security"},{"name":"libexiv2-doc","version":"0.27.2-8ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.27.2-8ubuntu2.2","pocket":"security"}],"groovy":[{"name":"exiv2","version":"0.27.3-3ubuntu0.2","description":"EXIF/IPTC/XMP metadata manipulation tool","is_source":true},{"name":"exiv2","version":"0.27.3-3ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.27.3-3ubuntu0.2","pocket":"security"},{"name":"libexiv2-27","version":"0.27.3-3ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.27.3-3ubuntu0.2","pocket":"security"},{"name":"libexiv2-dev","version":"0.27.3-3ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.27.3-3ubuntu0.2","pocket":"security"},{"name":"libexiv2-doc","version":"0.27.3-3ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.27.3-3ubuntu0.2","pocket":"security"}],"hirsute":[{"name":"exiv2","version":"0.27.3-3ubuntu1.1","description":"EXIF/IPTC/XMP metadata manipulation tool","is_source":true},{"name":"exiv2","version":"0.27.3-3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.27.3-3ubuntu1.1","pocket":"security"},{"name":"libexiv2-27","version":"0.27.3-3ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.27.3-3ubuntu1.1","pocket":"security"},{"name":"libexiv2-dev","version":"0.27.3-3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.27.3-3ubuntu1.1","pocket":"security"},{"name":"libexiv2-doc","version":"0.27.3-3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.27.3-3ubuntu1.1","pocket":"security"}],"xenial":[{"name":"exiv2","version":"0.25-2.1ubuntu16.04.7+esm1","description":"EXIF/IPTC/XMP metadata manipulation tool","is_source":true},{"name":"exiv2","version":"0.25-2.1ubuntu16.04.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":null,"pocket":"esm-infra"},{"name":"libexiv2-14","version":"0.25-2.1ubuntu16.04.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":null,"pocket":"esm-infra"},{"name":"libexiv2-dev","version":"0.25-2.1ubuntu16.04.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":null,"pocket":"esm-infra"},{"name":"libexiv2-doc","version":"0.25-2.1ubuntu16.04.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2021-29458","CVE-2021-3482","CVE-2021-29470","CVE-2021-29457"]}]},{"id":"CVE-2021-29457","published":"2021-04-19T19:15:00","updated_at":"2025-08-25T23:34:34.563621+00:00","description":"\nExiv2 is a command-line utility and C++ library for reading, writing,\ndeleting, and modifying the metadata of image files. A heap buffer overflow\nwas found in Exiv2 versions v0.27.3 and earlier. The heap overflow is\ntriggered when Exiv2 is used to write metadata into a crafted image file.\nAn attacker could potentially exploit the vulnerability to gain code\nexecution, if they can trick the victim into running Exiv2 on a crafted\nimage file. Note that this bug is only triggered when _writing_ the\nmetadata, which is a less frequently used Exiv2 operation than _reading_\nthe metadata. For example, to trigger the bug in the Exiv2 command-line\napplication, you need to add an extra command-line argument such as\n`insert`. The bug is fixed in version v0.27.4.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/Exiv2/exiv2/security/advisories/GHSA-v74w-h496-cgqm","https://github.com/Exiv2/exiv2/issues/1529","https://github.com/Exiv2/exiv2/pull/1534","https://ubuntu.com/security/notices/USN-4941-1","https://www.cve.org/CVERecord?id=CVE-2021-29457"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/exiv2/+bug/1923479"],"patches":{"exiv2":["upstream: https://github.com/Exiv2/exiv2/pull/1534/commits/13e5a3e02339b746abcaee6408893ca2fd8e289d"]},"tags":{},"packages":[{"name":"exiv2","source":"https://ubuntu.com/security/cve?package=exiv2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=exiv2","debian":"https://tracker.debian.org/pkg/exiv2","statuses":[{"release_codename":"jammy","status":"released","description":"0.27.3-3ubuntu2","component":null,"pocket":"security"},{"release_codename":"impish","status":"released","description":"0.27.3-3ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"0.25-3.1ubuntu0.18.04.7","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"0.27.2-8ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"groovy","status":"released","description":"0.27.3-3ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"released","description":"0.27.3-3ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.25-2.1ubuntu16.04.7+esm1","component":null,"pocket":"esm-infra"}]}],"notices_ids":["USN-4941-1"],"notices":[{"id":"USN-4941-1","title":"Exiv2 vulnerabilities","summary":"Several security issues were fixed in Exiv2.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-05-10T18:07:19.189006","description":"It was discovered that Exiv2 incorrectly handled certain images.\nAn attacker could possibly use this issue to execute arbitrary code or cause\na crash. (CVE-2021-29457)\n\nIt was discovered that Exiv2 incorrectly handled certain images.\nAn attacker could possibly use this issue to cause a denial of service.\n(CVE-2021-29458, CVE-2021-29470)\n\nIt was discovered that Exiv2 incorrectly handled certain images.\nAn attacker could possibly use this issue to execute arbitrary code or\ncause a crash. (CVE-2021-3482)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"exiv2","version":"0.25-3.1ubuntu0.18.04.7","description":"EXIF/IPTC/XMP metadata manipulation tool","is_source":true},{"name":"exiv2","version":"0.25-3.1ubuntu0.18.04.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.25-3.1ubuntu0.18.04.7","pocket":"security"},{"name":"libexiv2-14","version":"0.25-3.1ubuntu0.18.04.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.25-3.1ubuntu0.18.04.7","pocket":"security"},{"name":"libexiv2-dev","version":"0.25-3.1ubuntu0.18.04.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.25-3.1ubuntu0.18.04.7","pocket":"security"},{"name":"libexiv2-doc","version":"0.25-3.1ubuntu0.18.04.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.25-3.1ubuntu0.18.04.7","pocket":"security"}],"focal":[{"name":"exiv2","version":"0.27.2-8ubuntu2.2","description":"EXIF/IPTC/XMP metadata manipulation tool","is_source":true},{"name":"exiv2","version":"0.27.2-8ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.27.2-8ubuntu2.2","pocket":"security"},{"name":"libexiv2-27","version":"0.27.2-8ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.27.2-8ubuntu2.2","pocket":"security"},{"name":"libexiv2-dev","version":"0.27.2-8ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.27.2-8ubuntu2.2","pocket":"security"},{"name":"libexiv2-doc","version":"0.27.2-8ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.27.2-8ubuntu2.2","pocket":"security"}],"groovy":[{"name":"exiv2","version":"0.27.3-3ubuntu0.2","description":"EXIF/IPTC/XMP metadata manipulation tool","is_source":true},{"name":"exiv2","version":"0.27.3-3ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.27.3-3ubuntu0.2","pocket":"security"},{"name":"libexiv2-27","version":"0.27.3-3ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.27.3-3ubuntu0.2","pocket":"security"},{"name":"libexiv2-dev","version":"0.27.3-3ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.27.3-3ubuntu0.2","pocket":"security"},{"name":"libexiv2-doc","version":"0.27.3-3ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.27.3-3ubuntu0.2","pocket":"security"}],"hirsute":[{"name":"exiv2","version":"0.27.3-3ubuntu1.1","description":"EXIF/IPTC/XMP metadata manipulation tool","is_source":true},{"name":"exiv2","version":"0.27.3-3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.27.3-3ubuntu1.1","pocket":"security"},{"name":"libexiv2-27","version":"0.27.3-3ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.27.3-3ubuntu1.1","pocket":"security"},{"name":"libexiv2-dev","version":"0.27.3-3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.27.3-3ubuntu1.1","pocket":"security"},{"name":"libexiv2-doc","version":"0.27.3-3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.27.3-3ubuntu1.1","pocket":"security"}],"xenial":[{"name":"exiv2","version":"0.25-2.1ubuntu16.04.7+esm1","description":"EXIF/IPTC/XMP metadata manipulation tool","is_source":true},{"name":"exiv2","version":"0.25-2.1ubuntu16.04.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":null,"pocket":"esm-infra"},{"name":"libexiv2-14","version":"0.25-2.1ubuntu16.04.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":null,"pocket":"esm-infra"},{"name":"libexiv2-dev","version":"0.25-2.1ubuntu16.04.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":null,"pocket":"esm-infra"},{"name":"libexiv2-doc","version":"0.25-2.1ubuntu16.04.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2021-29458","CVE-2021-3482","CVE-2021-29470","CVE-2021-29457"]}]}],"offset":42760,"limit":20,"total_results":79316}