CVE-2013-0899

opus < 1.0.2 - Denial of Service via Integer Overflow in Padding Implementation

Title source: llm
STIX 2.1

Description

Integer overflow in the padding implementation in the opus_packet_parse_impl function in src/opus_decoder.c in Opus before 1.0.2, as used in Google Chrome before 25.0.1364.97 on Windows and Linux and before 25.0.1364.99 on Mac OS X and other products, allows remote attackers to cause a denial of service (out-of-bounds read) via a long packet.

Scores

EPSS 0.0151
EPSS Percentile 71.2%

Details

CWE
CWE-190
Status published
Products (4)
google/chrome < 25.0.1364.97
opensuse/opensuse 12.1
opensuse/opensuse 12.2
opus-codec/opus < 1.0.2
Published Feb 23, 2013
Tracked Since Feb 18, 2026