Description
Buffer overflow in the vorbis_parse_setup_hdr_floors function in the Vorbis decoder in vorbisdec.c in libavcodec in FFmpeg through 1.1.3, as used in Google Chrome before 25.0.1364.97 on Windows and Linux and before 25.0.1364.99 on Mac OS X and other products, allows remote attackers to cause a denial of service (divide-by-zero error or out-of-bounds array access) or possibly have unspecified other impact via vectors involving a zero value for a bark map size.
References (6)
Core 6
Core References
Patch x_refsource_confirm
http://git.videolan.org/?p=ffmpeg.git%3Ba=commit%3Bh=2c16bf2de07c68513072bf3cc96401d2c6291a3e
Release Notes, Vendor Advisory x_refsource_confirm
http://googlechromereleases.blogspot.com/2013/02/stable-channel-update_21.html
Issue Tracking x_refsource_confirm
https://code.google.com/p/chromium/issues/detail?id=168473
Vendor Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1790-1
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2013-03/msg00045.html
Various Sources x_refsource_confirm
http://git.chromium.org/gitweb/?p=chromium/deps/ffmpeg.git%3Ba=commit%3Bh=e1e70d9bb9852b7d099379afc95531a632a20ba5
Scores
EPSS
0.0047
EPSS Percentile
64.6%
Details
CWE
CWE-120
Status
published
Products (6)
canonical/ubuntu_linux
12.04
canonical/ubuntu_linux
12.10
ffmpeg/ffmpeg
< 1.1.3
google/chrome
< 25.0.1364.99
opensuse/opensuse
12.1
opensuse/opensuse
12.2
Published
Feb 23, 2013
Tracked Since
Feb 18, 2026