Vulnerability Name: | CVE-2011-3893 (CCN-71264) | ||||||||||||||||
Assigned: | 2011-11-10 | ||||||||||||||||
Published: | 2011-11-10 | ||||||||||||||||
Updated: | 2020-05-08 | ||||||||||||||||
Summary: | Google Chrome before 15.0.874.120 does not properly implement the MKV and Vorbis media handlers, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors. | ||||||||||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
5.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-125 | ||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||
References: | Source: CONFIRM Type: Exploit, Issue Tracking, Patch, Vendor Advisory http://code.google.com/p/chromium/issues/detail?id=100492 Source: CONFIRM Type: Exploit, Issue Tracking, Patch, Vendor Advisory http://code.google.com/p/chromium/issues/detail?id=100543 Source: MITRE Type: CNA CVE-2011-3893 Source: CCN Type: FFmpeg Web site FFmpeg Source: CCN Type: Google Chrome Releases Web site Stable Channel Update Source: CONFIRM Type: Exploit, Vendor Advisory http://googlechromereleases.blogspot.com/2011/11/stable-channel-update.html Source: CCN Type: SA46815 Google Chrome Multiple Vulnerabilities Source: SECUNIA Type: Third Party Advisory 46933 Source: CCN Type: SA47383 FFmpeg Multiple Vulnerabilities Source: SECUNIA Type: Third Party Advisory 49089 Source: DEBIAN Type: DSA-2471 ffmpeg -- several vulnerabilities Source: CCN Type: OSVDB ID: 77033 Google Chrome MKV / Vorbis Media Handler Out-of-bounds Read Unspecified Remote DoS Source: CCN Type: OSVDB ID: 83055 FFmpeg Vorbis File Handling Unspecified Arbitrary Code Execution Source: CCN Type: BID-50642 Google Chrome Prior to 15.0.874.120 Multiple Security Vulnerabilities Source: CCN Type: BID-51307 FFmpeg Multiple Remote Vulnerabilities Source: XF Type: UNKNOWN google-chrome-mkv-code-exec(71264) Source: OVAL Type: Third Party Advisory oval:org.mitre.oval:def:14267 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |