CVE-2015-1258
published 2015-05-20CVE-2015-1258: Google Chrome before 43.0.2357.65 relies on libvpx code that was not built with an appropriate --size-limit value, which allows remote attackers to trigger a…
PriorityP433high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.40%
82.2th percentile
Google Chrome before 43.0.2357.65 relies on libvpx code that was not built with an appropriate --size-limit value, which allows remote attackers to trigger a negative value for a size field, and consequently cause a denial of service or possibly have unspecified other impact, via a crafted frame size in VP9 video data.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | libvpx | < libvpx 1.4.0-4 (bookworm) | libvpx 1.4.0-4 (bookworm) |
| chrome | <= 42.0.2311.152 | — | |
| webmproject | libvpx | >= 0 < 1.4.0-4 | 1.4.0-4 |
| webmproject | libvpx | >= 0 < 1.4.0-4 | 1.4.0-4 |
| webmproject | libvpx | >= 0 < 1.4.0-4 | 1.4.0-4 |
| webmproject | libvpx | >= 0 < 1.4.0-4 | 1.4.0-4 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mwxh-q8vv-r69f: Google Chrome before 43
ghsa_unreviewed·2022-05-17
CVE-2015-1258 [HIGH] GHSA-mwxh-q8vv-r69f: Google Chrome before 43
Google Chrome before 43.0.2357.65 relies on libvpx code that was not built with an appropriate --size-limit value, which allows remote attackers to trigger a negative value for a size field, and consequently cause a denial of service or possibly have unspecified other impact, via a crafted frame size in VP9 video data.
OSV
oxide-qt vulnerabilities
osv·2015-05-21·CVSS 7.5
CVE-2015-1253 [HIGH] oxide-qt vulnerabilities
oxide-qt vulnerabilities
Several security issues were discovered in the DOM implementation in
Blink. If a user were tricked in to opening a specially crafted website,
an attacker could potentially exploit these to bypass Same Origin Policy
restrictions. (CVE-2015-1253, CVE-2015-1254)
A use-after-free was discovered in the WebAudio implementation in
Chromium. If a user were tricked in to opening a specially crafted
website, an attacker could potentially exploit this to cause a denial of
service via renderer crash, or execute arbitrary code with the privileges
of the sandboxed render process. (CVE-2015-1255)
A use-after-free was discovered in the SVG implementation in Blink. If a
user were tricked in to opening a specially crafted website, an attacker
could potentially exploit this to cau
OSV
CVE-2015-1258: Google Chrome before 43
osv·2015-05-20·CVSS 7.5
CVE-2015-1258 [HIGH] CVE-2015-1258: Google Chrome before 43
Google Chrome before 43.0.2357.65 relies on libvpx code that was not built with an appropriate --size-limit value, which allows remote attackers to trigger a negative value for a size field, and consequently cause a denial of service or possibly have unspecified other impact, via a crafted frame size in VP9 video data.
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2015-05-21·CVSS 7.5
CVE-2015-1253 [HIGH] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
Several security issues were discovered in the DOM implementation in
Blink. If a user were tricked in to opening a specially crafted website,
an attacker could potentially exploit these to bypass Same Origin Policy
restrictions. (CVE-2015-1253, CVE-2015-1254)
A use-after-free was discovered in the WebAudio implementation in
Chromium. If a user were tricked in to opening a specially crafted
website, an attacker could potentially exploit this to cause a denial of
service via renderer crash, or execute arbitrary code with the privileges
of the sandboxed render process. (CVE-2015-1255)
A use-after-free was discovered in the SVG implementation in Blink. If a
user were tricked in to opening a specially crafted
Red Hat
chromium-browser: Negative-size parameter in Libvpx.
vendor_redhat·2015-05-19·CVSS 7.5
CVE-2015-1258 [HIGH] chromium-browser: Negative-size parameter in Libvpx.
chromium-browser: Negative-size parameter in Libvpx.
Google Chrome before 43.0.2357.65 relies on libvpx code that was not built with an appropriate --size-limit value, which allows remote attackers to trigger a negative value for a size field, and consequently cause a denial of service or possibly have unspecified other impact, via a crafted frame size in VP9 video data.
Package: libvpx (Red Hat Enterprise Linux 6) - Will not fix
Package: libvpx (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2015-1258: libvpx - Google Chrome before 43.0.2357.65 relies on libvpx code that was not built with ...
vendor_debian·2015·CVSS 7.5
CVE-2015-1258 [HIGH] CVE-2015-1258: libvpx - Google Chrome before 43.0.2357.65 relies on libvpx code that was not built with ...
Google Chrome before 43.0.2357.65 relies on libvpx code that was not built with an appropriate --size-limit value, which allows remote attackers to trigger a negative value for a size field, and consequently cause a denial of service or possibly have unspecified other impact, via a crafted frame size in VP9 video data.
Scope: local
bookworm: resolved (fixed in 1.4.0-4)
bullseye: resolved (fixed in 1.4.0-4)
forky: resolved (fixed in 1.4.0-4)
sid: resolved (fixed in 1.4.0-4)
trixie: resolved (fixed in 1.4.0-4)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-1258 libvpx: chromium-browser: Negative-size parameter in Libvpx. [fedora-all]
bugzilla·2015-05-28·CVSS 7.5
CVE-2015-1258 [HIGH] CVE-2015-1258 libvpx: chromium-browser: Negative-size parameter in Libvpx. [fedora-all]
CVE-2015-1258 libvpx: chromium-browser: Negative-size parameter in Libvpx. [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ve
Bugzilla
CVE-2015-1258 chromium-browser: Negative-size parameter in Libvpx.
bugzilla·2015-05-20·CVSS 7.5
CVE-2015-1258 [HIGH] CVE-2015-1258 chromium-browser: Negative-size parameter in Libvpx.
CVE-2015-1258 chromium-browser: Negative-size parameter in Libvpx.
An unspecified negative-size parameter flaw was found in the Libvpx. component of the Chromium browser.
Upstream bug: https://code.google.com/p/chromium/issues/detail?id=450939
External References:
http://googlechromereleases.blogspot.com/2015/05/stable-channel-update_19.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:1023 https://rhn.redhat.com/errata/RHSA-2015-1023.html
---
This issue was fixed in chromium, by limiting the size of the input stream to be 16384x16384.
The following chromium commit (in embedded libvpx) fixes the issue:
https://chromium.googlesource.com/chromium/deps/libvpx/+/306d74445e38b203c38f222f7deecf6742962
http://googlechromereleases.blogspot.com/2015/05/stable-channel-update_19.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/168803.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/166975.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/167428.htmlhttp://lists.opensuse.org/opensuse-updates/2015-05/msg00091.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00015.htmlhttp://www.debian.org/security/2015/dsa-3267http://www.securityfocus.com/bid/74723http://www.securitytracker.com/id/1032375https://code.google.com/p/chromium/issues/detail?id=450939https://codereview.chromium.org/1106303002https://security.gentoo.org/glsa/201506-04http://googlechromereleases.blogspot.com/2015/05/stable-channel-update_19.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/168803.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/166975.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/167428.htmlhttp://lists.opensuse.org/opensuse-updates/2015-05/msg00091.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00015.htmlhttp://www.debian.org/security/2015/dsa-3267http://www.securityfocus.com/bid/74723http://www.securitytracker.com/id/1032375https://code.google.com/p/chromium/issues/detail?id=450939https://codereview.chromium.org/1106303002https://security.gentoo.org/glsa/201506-04
2015-05-20
Published