5
CVSSv2

CVE-2013-0899

Published: 23/02/2013 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Integer overflow in the padding implementation in the opus_packet_parse_impl function in src/opus_decoder.c in Opus prior to 1.0.2, as used in Google Chrome prior to 25.0.1364.97 on Windows and Linux and prior to 25.0.1364.99 on Mac OS X and other products, allows remote malicious users to cause a denial of service (out-of-bounds read) via a long packet.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

opus-codec opus

google chrome

opensuse opensuse 12.2

opensuse opensuse 12.1

Vendor Advisories

Debian Bug report logs - #704870 opus: cve-2013-0899 Package: opus; Maintainer for opus is Ron Lee <ron@debianorg>; Reported by: Michael Gilbert <mgilbert@debianorg> Date: Sun, 7 Apr 2013 00:03:02 UTC Severity: serious Tags: patch, security Found in version 0914+20120615-1 Fixed in versions 11~alpha+20130512-1 ...