IT

Tracker / CVE-2013-0899

CVE-2013-0899

Medium 5.0

Integer overflow in the padding implementation in the opus_packet_parse_impl function in src/opus_decoder.c in Opus before 1.0.2, as used in Google Chrome before 25.0.1364.97 on Windows and Linux and before 25.0.1364.99 on Mac OS X and other products, allows remote attackers to cause a denial of service (out-of-bounds read) via a long packet.

Affected products and versions

google chrome · … → 25.0.1364.97
google chrome · … → 25.0.1364.99
opensuse opensuse
opus-codec opus · … → 1.0.2

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References