UBUNTU-CVE-2015-6761
Dashboard / Vulnerabilities / UBUNTU-CVE-2015-6761
UBUNTU-CVE-2015-6761
Summary:
Details: The update_dimensions function in libavcodec/vp8.c in FFmpeg through 2.8.1, as used in Google Chrome before 46.0.2490.71 and other products, relies on a coefficient-partition count during multi-threaded operation, which allows remote attackers to cause a denial of service (race condition and memory corruption) or possibly have unspecified other impact via a crafted WebM file.
References: https://ubuntu.com/security/CVE-2015-6761, https://code.google.com/p/chromium/issues/detail?id=447860, https://code.google.com/p/chromium/issues/detail?id=532967, http://googlechromereleases.blogspot.com/2015/10/stable-channel-update.html, https://codereview.chromium.org/1376913003, https://ubuntu.com/security/notices/USN-2770-1, https://ubuntu.com/security/notices/USN-2770-2, https://www.cve.org/CVERecord?id=CVE-2015-6761
Affected packages
Package
Name: chromium-browser
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
