CVE-2011-0480
Publication date 14 January 2011
Last updated 24 July 2024
Ubuntu priority
Multiple buffer overflows in vorbis_dec.c in the Vorbis decoder in FFmpeg, as used in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344, allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted WebM file, related to buffers for (1) the channel floor and (2) the channel residue.
Status
Package | Ubuntu Release | Status |
---|---|---|
chromium-browser | 10.10 maverick |
Fixed 8.0.552.237~r70801-0ubuntu0.10.10.1
|
10.04 LTS lucid |
Fixed 8.0.552.237~r70801-0ubuntu0.10.04.1
|
|
9.10 karmic | Not in release | |
8.04 LTS hardy | Not in release | |
6.06 LTS dapper | Not in release | |
ffmpeg | 10.10 maverick |
Fixed 4:0.6-2ubuntu6.1
|
10.04 LTS lucid |
Fixed 4:0.5.1-1ubuntu1.1
|
|
9.10 karmic |
Fixed 4:0.5+svn20090706-2ubuntu2.3
|
|
8.04 LTS hardy |
Fixed 3:0.cvs20070307-5ubuntu7.6
|
|
6.06 LTS dapper | Ignored end of life | |
libav | 10.10 maverick | Not in release |
10.04 LTS lucid | Not in release | |
9.10 karmic | Not in release | |
8.04 LTS hardy | Not in release | |
6.06 LTS dapper | Not in release |
Patch details
Package | Patch details |
---|---|
ffmpeg | |
libav |
References
Related Ubuntu Security Notices (USN)
- USN-1104-1
- FFmpeg vulnerabilities
- 4 April 2011