PT-2014-1126 · FFmpeg+4 · Ffmpeg+4

Publicado

2014-06-10

·

Atualizado

2024-06-15

·

CVE-2014-3157

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 35.0.1916.153
Description The issue is related to a heap-based buffer overflow in the FFmpegVideoDecoder::GetVideoBuffer function, located in media/filters/ffmpeg video decoder.cc. This overflow occurs when handling VideoFrame data structures that are too small for proper interaction with the underlying FFmpeg library. Exploitation of this issue allows remote attackers to cause a denial of service or possibly have other unspecified impacts on the system.
Recommendations For versions prior to 35.0.1916.153, update to version 35.0.1916.153 or later to resolve the issue. As a temporary workaround, consider restricting the use of the FFmpegVideoDecoder::GetVideoBuffer function until a patch is applied.

Exploit

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-1955
BDU:2014-00209
CVE-2014-3157
DSA-2959-1
OPENSUSE-SU-2014_0982-1
OPENSUSE-SU-2024:10171-1
OPENSUSE-SU-2024:12948-1
USN-2298-1

Produtos afetados

Alt Linux
Ffmpeg
Google Chrome
Suse
Ubuntu