Use-after-free vulnerability in the Channel::SendRTCPPacket function in voice_engine/channel.cc in libjingle in WebRTC, as used in Google Chrome before 31.0.1650.48 and other products, allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via vectors that trigger the absence of certain statistics initialization, leading to the skipping of a required DeRegisterExternalTransport call.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Google Chrome | — | Upgrade to the latest version of Google Chrome | Nov 22, 2013 | Nov 12, 2013 |
| Suse | — | Upgrade chromium-desktop-kdeUpgrade chromium-desktop-gnomeUpgrade chromedriverUpgrade chromium-suid-helperUpgrade chromium-ffmpegsumoUpgrade chromium | Feb 17, 2015 | Nov 18, 2013 |
| Ubuntu | — | Upgrade chromium-browser | Nov 19, 2024 | Nov 19, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub