CVE-2010-4489Improper Restriction of Operations within the Bounds of a Memory Buffer in Google Chrome

Severity
4.3MEDIUMNVD
EPSS
0.8%
top 26.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 7
Latest updateMay 17

Description

libvpx, as used in Google Chrome before 8.0.552.215 and possibly other products, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WebM video. NOTE: this vulnerability exists because of a regression.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

Debianwebmproject/libvpx< 0.9.5-1+3
NVDgoogle/chrome8.0.552.214

🔴Vulnerability Details

3
GHSA
GHSA-wm8g-vw77-56hq: libvpx, as used in Google Chrome before 82022-05-17
OSV
CVE-2010-4489: libvpx, as used in Google Chrome before 82010-12-07
CVEList
CVE-2010-4489: libvpx, as used in Google Chrome before 82010-12-07

📋Vendor Advisories

3
Ubuntu
libvpx vulnerability2011-03-11
Red Hat
libvpx: Signedness error in partition size check2011-01-19
Debian
CVE-2010-4489: libvpx - libvpx, as used in Google Chrome before 8.0.552.215 and possibly other products,...2010

💬Community

1
Bugzilla
CVE-2010-4489 libvpx: Signedness error in partition size check2011-01-19
CVE-2010-4489 — Google Chrome vulnerability | cvebase