[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2013-0894Date: (C)2013-02-24   (M)2023-12-22


Buffer overflow in the vorbis_parse_setup_hdr_floors function in the Vorbis decoder in vorbisdec.c in libavcodec in FFmpeg through 1.1.3, as used in Google Chrome before 25.0.1364.97 on Windows and Linux and before 25.0.1364.99 on Mac OS X and other products, allows remote attackers to cause a denial of service (divide-by-zero error or out-of-bounds array access) or possibly have unspecified other impact via vectors involving a zero value for a bark map size.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.5
Exploit Score: 10.0
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
IAVM:2013-B-0016
USN-1790-1
http://git.chromium.org/gitweb/?p=chromium/deps/ffmpeg.git%3Ba=commit%3Bh=e1e70d9bb9852b7d099379afc95531a632a20ba5
http://git.chromium.org/gitweb/?p=chromium/deps/ffmpeg.git;a=commit;h=e1e70d9bb9852b7d099379afc95531a632a20ba5
http://git.videolan.org/?p=ffmpeg.git%3Ba=commit%3Bh=2c16bf2de07c68513072bf3cc96401d2c6291a3e
http://git.videolan.org/?p=ffmpeg.git;a=commit;h=2c16bf2de07c68513072bf3cc96401d2c6291a3e
http://googlechromereleases.blogspot.com/2013/02/stable-channel-update_21.html
https://code.google.com/p/chromium/issues/detail?id=168473
openSUSE-SU-2013:0454

CPE    91
cpe:/a:google:chrome:25.0.1364.52
cpe:/a:google:chrome:25.0.1364.51
cpe:/a:google:chrome:25.0.1364.50
cpe:/a:google:chrome:25.0.1364.58
...
CWE    1
CWE-119
OVAL    9
oval:org.secpod.oval:def:701246
oval:org.secpod.oval:def:9541
oval:org.secpod.oval:def:9611
oval:org.secpod.oval:def:9562
...

© SecPod Technologies