PT-2015-2400 · Google+5 · Google Chrome+5
Published
2015-10-15
·
Updated
2024-06-15
·
CVE-2015-6761
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
FFmpeg versions through 2.8.1
Google Chrome versions prior to 46.0.2490.71
Description
The issue is related to the update dimensions function in libavcodec/vp8.c, which relies on a coefficient-partition count during multi-threaded operation. This allows remote attackers to cause a denial of service (race condition and memory corruption) or possibly have unspecified other impact via a crafted WebM file. The vulnerability is caused by synchronization errors when using a shared resource.
Recommendations
For FFmpeg versions through 2.8.1, consider updating to a version that addresses the synchronization issue in the update dimensions function.
For Google Chrome versions prior to 46.0.2490.71, update to version 46.0.2490.71 or later to resolve the issue.
As a temporary workaround, consider disabling multi-threaded operation in FFmpeg until a patch is available.
Exploit
Fix
DoS
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Ffmpeg
Google Chrome
Opera
Red Hat
Ubuntu