CVE-2010-4203
published 2010-11-06CVE-2010-4203: WebM libvpx (aka the VP8 Codec SDK) before 0.9.5, as used in Google Chrome before 7.0.517.44, allows remote attackers to cause a denial of service (memory…
PriorityP341critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
4.57%
90.5th percentile
WebM libvpx (aka the VP8 Codec SDK) before 0.9.5, as used in Google Chrome before 7.0.517.44, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via invalid frames.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libvpx | < libvpx 0.9.1-2 (bookworm) | libvpx 0.9.1-2 (bookworm) |
| chrome | < 7.0.517.44 | 7.0.517.44 | |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| webmproject | libvpx | < 0.9.5 | 0.9.5 |
| webmproject | libvpx | >= 0 < 0.9.1-2 | 0.9.1-2 |
| webmproject | libvpx | >= 0 < 0.9.1-2 | 0.9.1-2 |
| webmproject | libvpx | >= 0 < 0.9.1-2 | 0.9.1-2 |
| webmproject | libvpx | >= 0 < 0.9.1-2 | 0.9.1-2 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libvpx vulnerability
vendor_ubuntu·2010-11-10
CVE-2010-4203 libvpx vulnerability
Title: libvpx vulnerability
Summary: libvpx applications could be made to run programs as your login if it
opened a specially crafted file.
Christoph Diehl discovered that libvpx did not properly perform bounds
checking. If an application using libvpx opened a specially crafted
WebM file, an attacker could cause a denial of service or possibly execute
code as the user invoking the program.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libvpx: memory corruption flaw
vendor_redhat·2010-11-04·CVSS 9.8
CVE-2010-4203 [CRITICAL] libvpx: memory corruption flaw
libvpx: memory corruption flaw
WebM libvpx (aka the VP8 Codec SDK) before 0.9.5, as used in Google Chrome before 7.0.517.44, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via invalid frames.
Debian
CVE-2010-4203: libvpx - WebM libvpx (aka the VP8 Codec SDK) before 0.9.5, as used in Google Chrome befor...
vendor_debian·2010·CVSS 9.8
CVE-2010-4203 [CRITICAL] CVE-2010-4203: libvpx - WebM libvpx (aka the VP8 Codec SDK) before 0.9.5, as used in Google Chrome befor...
WebM libvpx (aka the VP8 Codec SDK) before 0.9.5, as used in Google Chrome before 7.0.517.44, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via invalid frames.
Scope: local
bookworm: resolved (fixed in 0.9.1-2)
bullseye: resolved (fixed in 0.9.1-2)
forky: resolved (fixed in 0.9.1-2)
sid: resolved (fixed in 0.9.1-2)
trixie: resolved (fixed in 0.9.1-2)
GHSA
GHSA-v9gv-2chp-hf2r: WebM libvpx (aka the VP8 Codec SDK) before 0
ghsa_unreviewed·2022-05-13
CVE-2010-4203 [CRITICAL] CWE-190 GHSA-v9gv-2chp-hf2r: WebM libvpx (aka the VP8 Codec SDK) before 0
WebM libvpx (aka the VP8 Codec SDK) before 0.9.5, as used in Google Chrome before 7.0.517.44, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via invalid frames.
OSV
CVE-2010-4203: WebM libvpx (aka the VP8 Codec SDK) before 0
osv·2010-11-06·CVSS 9.8
CVE-2010-4203 [CRITICAL] CVE-2010-4203: WebM libvpx (aka the VP8 Codec SDK) before 0
WebM libvpx (aka the VP8 Codec SDK) before 0.9.5, as used in Google Chrome before 7.0.517.44, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via invalid frames.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-4489 libvpx: Signedness error in partition size check
bugzilla·2011-01-19·CVSS 9.8
CVE-2010-4489 [CRITICAL] CVE-2010-4489 libvpx: Signedness error in partition size check
CVE-2010-4489 libvpx: Signedness error in partition size check
An integer signedness error, leading to out-of-bounds buffer read
was found in the way libvpx, VP8 Video Codec SDK, decoded certain
VP8 video frames. A remote attacker could trick a local victim
into opening a specially-crafted WebM video file in an application,
using libvpx library, leading to denial of service (particular
application crash).
References:
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4489
[2] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=610510
[3] http://code.google.com/p/chromium/issues/detail?id=61653#c51
Upstream changeset (not definitely sure, needs confirmation):
[4] http://review.webmproject.org/#change,1098
Discussion:
This issue affects the version of the libvpx package, as shipped
Bugzilla
CVE-2010-4203 libvpx: memory corruption flaw [fedora-all]
bugzilla·2010-11-11·CVSS 9.8
CVE-2010-4203 [CRITICAL] CVE-2010-4203 libvpx: memory corruption flaw [fedora-all]
CVE-2010-4203 libvpx: memory corruption flaw [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=651213
Please note: this issue affects multiple supported versio
Bugzilla
CVE-2010-4203 libvpx: memory corruption flaw
bugzilla·2010-11-09·CVSS 9.8
CVE-2010-4203 [CRITICAL] CVE-2010-4203 libvpx: memory corruption flaw
CVE-2010-4203 libvpx: memory corruption flaw
A recent Google Chrome update indicated there was a memory corruption flaw in libvpx [1].
Upstream changes to correct the flaw are here:
https://review.webmproject.org/#change,928
http://review.webmproject.org/#change,1098
(the second is to fix some regressions introduced by the first patch, by the looks of things).
libvpx seems to only be used, currently, by gstreamer-plugins-bad-free.
[1] http://googlechromereleases.blogspot.com/2010/11/stable-channel-update.html
Discussion:
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-4203 to
the following vulnerability:
Name: CVE-2010-4203
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4203
Assigned: 20101105
Reference: CONFIRM: http://code.google.com/p/chromium/
http://code.google.com/p/chromium/issues/detail?id=60055http://googlechromereleases.blogspot.com/2010/11/stable-channel-update.htmlhttp://review.webmproject.org/gitweb?p=libvpx.git%3Ba=blob%3Bf=CHANGELOGhttp://review.webmproject.org/gitweb?p=libvpx.git%3Ba=commit%3Bh=09bcc1f710ea65dc158639479288fb1908ff0c53http://secunia.com/advisories/42109http://secunia.com/advisories/42118http://secunia.com/advisories/42690http://secunia.com/advisories/42908http://security.gentoo.org/glsa/glsa-201101-03.xmlhttp://www.vupen.com/english/advisories/2011/0115https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12198https://rhn.redhat.com/errata/RHSA-2010-0999.htmlhttp://code.google.com/p/chromium/issues/detail?id=60055http://googlechromereleases.blogspot.com/2010/11/stable-channel-update.htmlhttp://review.webmproject.org/gitweb?p=libvpx.git%3Ba=blob%3Bf=CHANGELOGhttp://review.webmproject.org/gitweb?p=libvpx.git%3Ba=commit%3Bh=09bcc1f710ea65dc158639479288fb1908ff0c53http://secunia.com/advisories/42109http://secunia.com/advisories/42118http://secunia.com/advisories/42690http://secunia.com/advisories/42908http://security.gentoo.org/glsa/glsa-201101-03.xmlhttp://www.vupen.com/english/advisories/2011/0115https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12198https://rhn.redhat.com/errata/RHSA-2010-0999.html
2010-11-06
Published