CVE-2010-4489
published 2010-12-07CVE-2010-4489: libvpx, as used in Google Chrome before 8.0.552.215 and possibly other products, allows remote attackers to cause a denial of service (out-of-bounds read) via…
PriorityP413medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
1.01%
59.4th percentile
libvpx, as used in Google Chrome before 8.0.552.215 and possibly other products, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WebM video. NOTE: this vulnerability exists because of a regression.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libvpx | < libvpx 0.9.5-1 (bookworm) | libvpx 0.9.5-1 (bookworm) |
| chrome | <= 8.0.552.214 | — | |
| webmproject | libvpx | >= 0 < 0.9.5-1 | 0.9.5-1 |
| webmproject | libvpx | >= 0 < 0.9.5-1 | 0.9.5-1 |
| webmproject | libvpx | >= 0 < 0.9.5-1 | 0.9.5-1 |
| webmproject | libvpx | >= 0 < 0.9.5-1 | 0.9.5-1 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wm8g-vw77-56hq: libvpx, as used in Google Chrome before 8
ghsa_unreviewed·2022-05-17
CVE-2010-4489 [MEDIUM] CWE-119 GHSA-wm8g-vw77-56hq: libvpx, as used in Google Chrome before 8
libvpx, as used in Google Chrome before 8.0.552.215 and possibly other products, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WebM video. NOTE: this vulnerability exists because of a regression.
OSV
CVE-2010-4489: libvpx, as used in Google Chrome before 8
osv·2010-12-07·CVSS 4.3
CVE-2010-4489 [MEDIUM] CVE-2010-4489: libvpx, as used in Google Chrome before 8
libvpx, as used in Google Chrome before 8.0.552.215 and possibly other products, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WebM video. NOTE: this vulnerability exists because of a regression.
Ubuntu
libvpx vulnerability
vendor_ubuntu·2011-03-11
CVE-2010-4489 libvpx vulnerability
Title: libvpx vulnerability
Summary: libvpx DOS bad read
Chris Evans discovered that libvpx did not properly perform bounds
checking. If an application using libvpx opened a specially crafted WebM
file, an attacker could cause a denial of service.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.
Red Hat
libvpx: Signedness error in partition size check
vendor_redhat·2011-01-19·CVSS 4.3
CVE-2010-4489 [MEDIUM] libvpx: Signedness error in partition size check
libvpx: Signedness error in partition size check
libvpx, as used in Google Chrome before 8.0.552.215 and possibly other products, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WebM video. NOTE: this vulnerability exists because of a regression.
Statement: Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: libvpx (Red Hat Enterprise Linux 6) - Will not fix
Debian
CVE-2010-4489: libvpx - libvpx, as used in Google Chrome before 8.0.552.215 and possibly other products,...
vendor_debian·2010·CVSS 4.3
CVE-2010-4489 [MEDIUM] CVE-2010-4489: libvpx - libvpx, as used in Google Chrome before 8.0.552.215 and possibly other products,...
libvpx, as used in Google Chrome before 8.0.552.215 and possibly other products, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WebM video. NOTE: this vulnerability exists because of a regression.
Scope: local
bookworm: resolved (fixed in 0.9.5-1)
bullseye: resolved (fixed in 0.9.5-1)
forky: resolved (fixed in 0.9.5-1)
sid: resolved (fixed in 0.9.5-1)
trixie: resolved (fixed in 0.9.5-1)
No detection rules found.
No public exploits indexed.
http://code.google.com/p/chromium/issues/detail?id=61653http://googlechromereleases.blogspot.com/2010/12/stable-beta-channel-updates.htmlhttp://secunia.com/advisories/42472http://secunia.com/advisories/43728http://www.ubuntu.com/usn/USN-1087-1http://www.vupen.com/english/advisories/2011/0662https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11919http://code.google.com/p/chromium/issues/detail?id=61653http://googlechromereleases.blogspot.com/2010/12/stable-beta-channel-updates.htmlhttp://secunia.com/advisories/42472http://secunia.com/advisories/43728http://www.ubuntu.com/usn/USN-1087-1http://www.vupen.com/english/advisories/2011/0662https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11919
2010-12-07
Published