CVE-2011-3895Out-of-bounds Write in Google Chrome

Severity
7.5HIGHNVD
EPSS
3.4%
top 12.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 11
Latest updateMay 13

Description

Heap-based buffer overflow in the Vorbis decoder in Google Chrome before 15.0.874.120 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted stream.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages3 packages

NVDgoogle/chrome< 15.0.874.120
debiandebian/ffmpeg< ffmpeg 7:2.4.1-1 (bookworm)
Debianffmpeg/ffmpeg< 7:2.4.1-1+3

Also affects: Debian Linux 6.0

🔴Vulnerability Details

2
GHSA
GHSA-wwcc-3xpq-5gj8: Heap-based buffer overflow in the Vorbis decoder in Google Chrome before 152022-05-13
OSV
CVE-2011-3895: Heap-based buffer overflow in the Vorbis decoder in Google Chrome before 152011-11-11

📋Vendor Advisories

1
Debian
CVE-2011-3895: ffmpeg - Heap-based buffer overflow in the Vorbis decoder in Google Chrome before 15.0.87...2011