CVE-2011-0480

Google Chrome OS < 8.0.552.344 - Buffer Overflow

Title source: rule
STIX 2.1

Description

Multiple buffer overflows in vorbis_dec.c in the Vorbis decoder in FFmpeg, as used in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344, allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted WebM file, related to buffers for (1) the channel floor and (2) the channel residue.

References (20)

Core 20
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/42951
Broken Link x_refsource_confirm
http://roundup.ffmpeg.org/issue2548
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2011/dsa-2306
Broken Link mailing-list x_refsource_mlist
http://article.gmane.org/gmane.comp.video.ffmpeg.devel/122703
Issue Tracking, Third Party Advisory x_refsource_confirm
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=610550
Vendor Advisory x_refsource_confirm
http://codereview.chromium.org/6069005
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/45788
Third Party Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2011:061
Patch, Vendor Advisory x_refsource_confirm
http://codereview.chromium.org/5964011
Third Party Advisory x_refsource_confirm
http://www.srware.net/forum/viewtopic.php?f=18&t=2054
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-1104-1/
Broken Link vdb-entry x_refsource_osvdb
http://osvdb.org/70463
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/64671
Third Party Advisory x_refsource_confirm
http://ffmpeg.mplayerhq.hu/
Exploit, Issue Tracking, Patch, Vendor Advisory x_refsource_confirm
http://code.google.com/p/chromium/issues/detail?id=68115
Broken Link x_refsource_confirm
http://roundup.ffmpeg.org/issue2550

Scores

EPSS 0.0129
EPSS Percentile 79.8%

Details

CWE
CWE-120
Status published
Products (7)
canonical/ubuntu_linux 8.04
canonical/ubuntu_linux 9.10
canonical/ubuntu_linux 10.04
canonical/ubuntu_linux 10.10
debian/debian_linux 6.0
google/chrome < 8.0.552.237
google/chrome_os < 8.0.552.344
Published Jan 14, 2011
Tracked Since Feb 18, 2026