CVE-2011-3893
published 2011-11-11CVE-2011-3893: Google Chrome before 15.0.874.120 does not properly implement the MKV and Vorbis media handlers, which allows remote attackers to cause a denial of service…
PriorityP419medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.75%
75.5th percentile
Google Chrome before 15.0.874.120 does not properly implement the MKV and Vorbis media handlers, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 7:2.4.1-1 (bookworm) | ffmpeg 7:2.4.1-1 (bookworm) |
| ffmpeg | ffmpeg | <= 0.9 | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | >= 0 < 7:2.4.1-1 | 7:2.4.1-1 |
| ffmpeg | ffmpeg | >= 0 < 7:2.4.1-1 | 7:2.4.1-1 |
| ffmpeg | ffmpeg | >= 0 < 7:2.4.1-1 | 7:2.4.1-1 |
| ffmpeg | ffmpeg | >= 0 < 7:2.4.1-1 | 7:2.4.1-1 |
| chrome | < 15.0.874.120 | 15.0.874.120 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fcgq-p3x8-962w: The render_line function in the vorbis codec (vorbis
ghsa_unreviewed·2022-05-17·CVSS 5.0
CVE-2012-0859 [MEDIUM] CWE-119 GHSA-fcgq-p3x8-962w: The render_line function in the vorbis codec (vorbis
The render_line function in the vorbis codec (vorbis.c) in libavcodec in FFmpeg before 0.9.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted Vorbis file, related to a large multiplier. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3893.
GHSA
GHSA-3fv3-gc7v-qvm8: Google Chrome before 15
ghsa_unreviewed·2022-05-13
CVE-2011-3893 [MEDIUM] CWE-125 GHSA-3fv3-gc7v-qvm8: Google Chrome before 15
Google Chrome before 15.0.874.120 does not properly implement the MKV and Vorbis media handlers, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
OSV
CVE-2012-0859: The render_line function in the vorbis codec (vorbis
osv·2012-08-20·CVSS 5.0
CVE-2012-0859 [MEDIUM] CVE-2012-0859: The render_line function in the vorbis codec (vorbis
The render_line function in the vorbis codec (vorbis.c) in libavcodec in FFmpeg before 0.9.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted Vorbis file, related to a large multiplier. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3893.
OSV
CVE-2011-3893: Google Chrome before 15
osv·2011-11-11·CVSS 5.0
CVE-2011-3893 [MEDIUM] CVE-2011-3893: Google Chrome before 15
Google Chrome before 15.0.874.120 does not properly implement the MKV and Vorbis media handlers, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
Debian
CVE-2012-0859: ffmpeg - The render_line function in the vorbis codec (vorbis.c) in libavcodec in FFmpeg ...
vendor_debian·2012·CVSS 5.0
CVE-2012-0859 [MEDIUM] CVE-2012-0859: ffmpeg - The render_line function in the vorbis codec (vorbis.c) in libavcodec in FFmpeg ...
The render_line function in the vorbis codec (vorbis.c) in libavcodec in FFmpeg before 0.9.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted Vorbis file, related to a large multiplier. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3893.
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolved (fixed in 7:2.4.1-1)
sid: resolved (fixed in 7:2.4.1-1)
trixie: resolved (fixed in 7:2.4.1-1)
Debian
CVE-2011-3893: ffmpeg - Google Chrome before 15.0.874.120 does not properly implement the MKV and Vorbis...
vendor_debian·2011·CVSS 5.0
CVE-2011-3893 [MEDIUM] CVE-2011-3893: ffmpeg - Google Chrome before 15.0.874.120 does not properly implement the MKV and Vorbis...
Google Chrome before 15.0.874.120 does not properly implement the MKV and Vorbis media handlers, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 7:2.4.1-1)
bullseye: resolved (fixed in 7:2.4.1-1)
forky: resolved (fixed in 7:2.4.1-1)
sid: resolved (fixed in 7:2.4.1-1)
trixie: resolved (fixed in 7:2.4.1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://code.google.com/p/chromium/issues/detail?id=100492http://code.google.com/p/chromium/issues/detail?id=100543http://googlechromereleases.blogspot.com/2011/11/stable-channel-update.htmlhttp://secunia.com/advisories/46933http://secunia.com/advisories/49089https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14267http://code.google.com/p/chromium/issues/detail?id=100492http://code.google.com/p/chromium/issues/detail?id=100543http://googlechromereleases.blogspot.com/2011/11/stable-channel-update.htmlhttp://secunia.com/advisories/46933http://secunia.com/advisories/49089https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14267
2011-11-11
Published