Buffer overflow in the vorbis_parse_setup_hdr_floors function in the Vorbis decoder in vorbisdec.c in libavcodec in FFmpeg through 1.1.3, as used in Google Chrome before 25.0.1364.97 on Windows and Linux and before 25.0.1364.99 on Mac OS X and other products, allows remote attackers to cause a denial of service (divide-by-zero error or out-of-bounds array access) or possibly have unspecified other impact via vectors involving a zero value for a bark map size.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade ffmpeg | Jul 30, 2024 | Feb 23, 2013 |
| Ffmpeg | — | Upgrade to FFmpeg version 0.8.15Upgrade to FFmpeg version 0.10.7Upgrade to FFmpeg version 0.9.4Upgrade to FFmpeg version 1.1.4Upgrade to FFmpeg version 0.7.16Upgrade to FFmpeg version 1.0.10Upgrade to FFmpeg version 1.2 | Sep 29, 2017 | Feb 23, 2013 |
| Gentoo Linux | — | Upgrade www-client/chromium.Upgrade dev-lang/v8. | Oct 30, 2017 | Feb 23, 2013 |
| Google Chrome | — | Upgrade to the latest version of Google Chrome | Mar 3, 2013 | Feb 21, 2013 |
| Suse | — | Upgrade chromedriver-debuginfoUpgrade chromedriverUpgrade chromium-suid-helperUpgrade chromium-suid-helper-debuginfoUpgrade chromiumUpgrade chromium-debugsourceUpgrade chromium-ffmpegsumoUpgrade chromium-desktop-kdeUpgrade chromium-debuginfoUpgrade chromium-ffmpegsumo-debuginfoUpgrade chromium-desktop-gnome | Dec 12, 2013 | Feb 23, 2013 |
| Ubuntu | — | Upgrade libavcodec53Upgrade libavformat53 | Nov 8, 2024 | Feb 23, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub