Lucene search

K
freebsdFreeBSD6CA7EDDD-D436-486A-B169-B948436BCF14
HistorySep 22, 2015 - 12:00 a.m.

libvpx -- buffer overflow in vp9_init_context_buffers

2015-09-2200:00:00
vuxml.freebsd.org
20

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.093

Percentile

94.8%

The Mozilla Project reports:

Security researcher Khalil Zhani reported that a
maliciously crafted vp9 format video could be used to
trigger a buffer overflow while parsing the file. This leads
to a potentially exploitable crash due to a flaw in the
libvpx library.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchlibvpx< 1.4.0.488_1UNKNOWN

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.093

Percentile

94.8%