9.3
CVSSv2

CVE-2011-0480

Published: 14/01/2011 Updated: 07/11/2023
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple buffer overflows in vorbis_dec.c in the Vorbis decoder in FFmpeg, as used in Google Chrome prior to 8.0.552.237 and Chrome OS prior to 8.0.552.344, allow remote malicious users to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted WebM file, related to buffers for (1) the channel floor and (2) the channel residue.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome os

google chrome

debian debian linux 6.0

canonical ubuntu linux 10.10

canonical ubuntu linux 9.10

canonical ubuntu linux 8.04

canonical ubuntu linux 10.04

Vendor Advisories

FFmpeg could be made to run programs as your login if it opened a specially crafted file ...
Debian Bug report logs - #610550 [CVE-2011-0480] memory corruptions in the ffmpeg Vorbis codec Package: ffmpeg; Maintainer for ffmpeg is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Source for ffmpeg is src:ffmpeg (PTS, buildd, popcon) Reported by: Luciano Bello <luciano@debianorg> Date: Wed, ...
Debian Bug report logs - #611495 [CVE-2010-4705] [CVE-2010-4704] integer overflow in Vorbis decoder Package: ffmpeg; Maintainer for ffmpeg is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Source for ffmpeg is src:ffmpeg (PTS, buildd, popcon) Reported by: Luciano Bello <luciano@debianorg> Date: ...
Debian Bug report logs - #628448 several vulnerabilities: CVE-2011-2162 CVE-2011-2161 CVE-2011-2160 Package: libav; Maintainer for libav is Debian Multimedia Maintainers <pkg-multimedia-maintainers@listsaliothdebianorg>; Reported by: Steffen Joeris <white@debianorg> Date: Sun, 29 May 2011 03:27:01 UTC Severity: g ...