Heap-based buffer overflow in the FFmpegVideoDecoder::GetVideoBuffer function in media/filters/ffmpeg_video_decoder.cc in Google Chrome before 35.0.1916.153 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging VideoFrame data structures that are too small for proper interaction with an underlying FFmpeg library.
CVSS Details
- CVSS 3.1 Base Score: 6.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade www-client/chromium. | Oct 30, 2017 | Jun 11, 2014 |
| Google Chrome | — | Upgrade to the latest version of Google Chrome | Jun 13, 2014 | Jun 10, 2014 |
| Suse | — | Upgrade chromium | Dec 18, 2015 | Jun 11, 2014 |
| Ubuntu | — | Upgrade oxideqt-codecsUpgrade liboxideqtcore0Upgrade oxideqt-codecs-extra | Nov 8, 2024 | Jun 11, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub