CVE-2012-5144
published 2012-12-12CVE-2012-5144: Google Chrome before 23.0.1271.97, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.5, do not properly perform AAC decoding, which allows remote attackers to…
PriorityP433critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
3.53%
88.1th percentile
Google Chrome before 23.0.1271.97, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.5, do not properly perform AAC decoding, which allows remote attackers to cause a denial of service (stack memory corruption) or possibly have unspecified other impact via vectors related to "an off-by-one overwrite when switching to LTP profile from MAIN."
Affected
86 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | ffmpeg | — | — |
| chrome | <= 23.0.1271.96 | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_debian10.0LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Libav vulnerabilities
vendor_ubuntu·2013-01-28
CVE-2012-2783 Libav vulnerabilities
Title: Libav vulnerabilities
Summary: Libav could be made to crash or run programs as your login if it opened a
specially crafted file.
It was discovered that Libav incorrectly handled certain malformed media
files. If a user were tricked into opening a crafted media file, an
attacker could cause a denial of service via application crash, or possibly
execute arbitrary code with the privileges of the user invoking the
program.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2012-5144: ffmpeg - Google Chrome before 23.0.1271.97, and Libav 0.7.x before 0.7.7 and 0.8.x before...
vendor_debian·2012·CVSS 10.0
CVE-2012-5144 [CRITICAL] CVE-2012-5144: ffmpeg - Google Chrome before 23.0.1271.97, and Libav 0.7.x before 0.7.7 and 0.8.x before...
Google Chrome before 23.0.1271.97, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.5, do not properly perform AAC decoding, which allows remote attackers to cause a denial of service (stack memory corruption) or possibly have unspecified other impact via vectors related to "an off-by-one overwrite when switching to LTP profile from MAIN."
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-6c83-9pcg-77c5: Google Chrome before 23
ghsa_unreviewed·2022-05-14
CVE-2012-5144 [HIGH] CWE-119 GHSA-6c83-9pcg-77c5: Google Chrome before 23
Google Chrome before 23.0.1271.97, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.5, do not properly perform AAC decoding, which allows remote attackers to cause a denial of service (stack memory corruption) or possibly have unspecified other impact via vectors related to "an off-by-one overwrite when switching to LTP profile from MAIN."
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://googlechromereleases.blogspot.com/2012/12/stable-channel-update.htmlhttp://libav.org/releases/libav-0.7.7.changeloghttp://libav.org/releases/libav-0.8.5.changeloghttp://lists.opensuse.org/opensuse-updates/2012-12/msg00073.htmlhttp://www.ubuntu.com/usn/USN-1705-1https://code.google.com/p/chromium/issues/detail?id=161639https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16007http://googlechromereleases.blogspot.com/2012/12/stable-channel-update.htmlhttp://libav.org/releases/libav-0.7.7.changeloghttp://libav.org/releases/libav-0.8.5.changeloghttp://lists.opensuse.org/opensuse-updates/2012-12/msg00073.htmlhttp://www.ubuntu.com/usn/USN-1705-1https://code.google.com/p/chromium/issues/detail?id=161639https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16007
2012-12-12
Published