Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-5283

Опубликовано: 27 мая 2025
Источник: debian

Описание

Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

Пакеты

ПакетСтатусВерсия исправленияРелизТип
chromiumfixed137.0.7151.55-1package
chromiumend-of-lifebullseyepackage
firefoxfixed139.0-1package
firefox-esrfixed128.11.0esr-1package
thunderbirdfixed1:128.11.0esr-1package
libvpxfixed1.15.0-2.1package

Примечания

  • Fixed by: https://chromium.googlesource.com/webm/libvpx/+/1c758781c428c0e895645b95b8ff1512b6bdcecb

  • https://www.mozilla.org/en-US/security/advisories/mfsa2025-42/#CVE-2025-5283

  • https://www.mozilla.org/en-US/security/advisories/mfsa2025-44/#CVE-2025-5283

  • https://www.mozilla.org/en-US/security/advisories/mfsa2025-46/#CVE-2025-5283

Связанные уязвимости

CVSS3: 5.4
ubuntu
22 дня назад

Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 8.1
redhat
22 дня назад

Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 5.4
nvd
22 дня назад

Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

msrc
20 дней назад

Chromium: CVE-2025-5283 Use after free in libvpx

CVSS3: 5.4
github
22 дня назад

Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)