PT-2015-1197 · Opera+4 · Opera+5

Cloudfuzzer

·

Publicado

2015-05-19

·

Atualizado

2024-06-15

·

CVE-2015-1258

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 43.0.2357.65 Opera (affected versions not specified) libvpx (affected versions not specified)
Description The issue allows a remote attacker to cause a denial of service by initializing fields with a negative size through the use of specially crafted VP9 video frames. This is due to the libvpx code not being built with an appropriate --size-limit value. The attacker can trigger a negative value for a size field, potentially having unspecified other impacts.
Recommendations For Google Chrome versions prior to 43.0.2357.65, update to version 43.0.2357.65 or later. For Opera, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting the use of VP9 video data in affected browsers until a patch is available.

Exploit

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-1589
BDU:2015-10131
CVE-2015-1258
DSA-3267-1
MGASA-2015-0235
MGASA-2015-0249
OPENSUSE-SU-2024:10171-1
OPENSUSE-SU-2024:12948-1
RHSA-2015:1023
RHSA-2015_1023
USN-2610-1

Produtos afetados

Alt Linux
Google Chrome
Opera
Red Hat
Ubuntu
Libvpx