Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6c83-9pcg-77c5

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Google Chrome before 23.0.1271.97, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.5, do not properly perform AAC decoding, which allows remote attackers to cause a denial of service (stack memory corruption) or possibly have unspecified other impact via vectors related to "an off-by-one overwrite when switching to LTP profile from MAIN."

Google Chrome before 23.0.1271.97, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.5, do not properly perform AAC decoding, which allows remote attackers to cause a denial of service (stack memory corruption) or possibly have unspecified other impact via vectors related to "an off-by-one overwrite when switching to LTP profile from MAIN."

EPSS

Процентиль: 87%
0.03505
Низкий

Дефекты

CWE-119

Связанные уязвимости

ubuntu
около 13 лет назад

Google Chrome before 23.0.1271.97, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.5, do not properly perform AAC decoding, which allows remote attackers to cause a denial of service (stack memory corruption) or possibly have unspecified other impact via vectors related to "an off-by-one overwrite when switching to LTP profile from MAIN."

nvd
около 13 лет назад

Google Chrome before 23.0.1271.97, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.5, do not properly perform AAC decoding, which allows remote attackers to cause a denial of service (stack memory corruption) or possibly have unspecified other impact via vectors related to "an off-by-one overwrite when switching to LTP profile from MAIN."

debian
около 13 лет назад

Google Chrome before 23.0.1271.97, and Libav 0.7.x before 0.7.7 and 0. ...

EPSS

Процентиль: 87%
0.03505
Низкий

Дефекты

CWE-119