CVE-2011-3892
published 2011-11-11CVE-2011-3892: Double free vulnerability in the Theora decoder in Google Chrome before 15.0.874.120 allows remote attackers to cause a denial of service or possibly have…
PriorityP429high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.80%
76.3th percentile
Double free vulnerability in the Theora decoder in Google Chrome before 15.0.874.120 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted stream.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | ffmpeg | < ffmpeg 7:2.4.1-1 (bookworm) | ffmpeg 7:2.4.1-1 (bookworm) |
| ffmpeg | ffmpeg | >= 0 < 7:2.4.1-1 | 7:2.4.1-1 |
| ffmpeg | ffmpeg | >= 0 < 7:2.4.1-1 | 7:2.4.1-1 |
| ffmpeg | ffmpeg | >= 0 < 7:2.4.1-1 | 7:2.4.1-1 |
| ffmpeg | ffmpeg | >= 0 < 7:2.4.1-1 | 7:2.4.1-1 |
| chrome | < 15.0.874.120 | 15.0.874.120 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m8q7-4f56-chp9: Double free vulnerability in the Theora decoder in Google Chrome before 15
ghsa_unreviewed·2022-05-13
CVE-2011-3892 [HIGH] CWE-415 GHSA-m8q7-4f56-chp9: Double free vulnerability in the Theora decoder in Google Chrome before 15
Double free vulnerability in the Theora decoder in Google Chrome before 15.0.874.120 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted stream.
OSV
CVE-2011-3892: Double free vulnerability in the Theora decoder in Google Chrome before 15
osv·2011-11-11·CVSS 7.5
CVE-2011-3892 [HIGH] CVE-2011-3892: Double free vulnerability in the Theora decoder in Google Chrome before 15
Double free vulnerability in the Theora decoder in Google Chrome before 15.0.874.120 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted stream.
Debian
CVE-2011-3892: ffmpeg - Double free vulnerability in the Theora decoder in Google Chrome before 15.0.874...
vendor_debian·2011·CVSS 7.5
CVE-2011-3892 [HIGH] CVE-2011-3892: ffmpeg - Double free vulnerability in the Theora decoder in Google Chrome before 15.0.874...
Double free vulnerability in the Theora decoder in Google Chrome before 15.0.874.120 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted stream.
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolved (fixed in 7:2.4.1-1)
sid: resolved (fixed in 7:2.4.1-1)
trixie: resolved (fixed in 7:2.4.1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
Update libtheora to latest version (7180717276af1ebc7da15c83162d6c5d6203aabf)
bugzilla·2021-11-18·CVSS 7.5
CVE-2011-3892 [HIGH] Update libtheora to latest version (7180717276af1ebc7da15c83162d6c5d6203aabf)
Update libtheora to latest version (7180717276af1ebc7da15c83162d6c5d6203aabf)
Theora hasn't been updated since 2010 and while I could only find one CVE linked to libtheora in that time (https://nvd.nist.gov/vuln/detail/CVE-2011-3892) and I think this is most likely pretty low severity, it would be great to update it before we land the patch to enable it in Updatebot.
I've erred on the side of caution and marked this as a security issue due to the amount of time since the last update.
Discussion:
Created attachment 9251365
Bug 1741873 - Update libtheora to latest; r=bryce,tjr
---
"There was a double-free hiding behind the relatively harmless OOB read, so therefore a $500 Chromium Security Reward!"
---
FWIW the test movie from crbug/100465 doesn't crash a release version of Firefox o
Bugzilla
CVE-2009-3892 Request Tracker XSS flaw [F11]
bugzilla·2009-11-17·CVSS 4.3
CVE-2009-3892 [MEDIUM] CVE-2009-3892 Request Tracker XSS flaw [F11]
CVE-2009-3892 Request Tracker XSS flaw [F11]
F11 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
You can eventually use the following link to create the update request:
https://admin.fedoraproject.org/updates/new/?request=Stable&type_=security&release=Fedora%2011&bugs=538175,
---
*** This bug has been marked as a duplicate of bug 526870 ***
http://code.google.com/p/chromium/issues/detail?id=100465http://googlechromereleases.blogspot.com/2011/11/stable-channel-update.htmlhttp://secunia.com/advisories/46933http://secunia.com/advisories/49089http://www.debian.org/security/2012/dsa-2471http://www.mandriva.com/security/advisories?name=MDVSA-2012:075http://www.mandriva.com/security/advisories?name=MDVSA-2012:076https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14484http://code.google.com/p/chromium/issues/detail?id=100465http://googlechromereleases.blogspot.com/2011/11/stable-channel-update.htmlhttp://secunia.com/advisories/46933http://secunia.com/advisories/49089http://www.debian.org/security/2012/dsa-2471http://www.mandriva.com/security/advisories?name=MDVSA-2012:075http://www.mandriva.com/security/advisories?name=MDVSA-2012:076https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14484
2011-11-11
Published