Vulnerability Name: CVE-2012-2882 (CCN-78839) Assigned: 2012-09-25 Published: 2012-09-25 Updated: 2018-10-30 Summary: FFmpeg, as used in Google Chrome before 22.0.1229.79, does not properly handle OGG containers, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors, related to a "wild pointer" issue. CVSS v3 Severity: 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): ChangedImpact Metrics: Confidentiality (C): HighIntegrity (I): HighAvailibility (A): High
CVSS v2 Severity: 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P )5.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAuthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): PartialAvailibility (A): Partial
9.3 High (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C )6.9 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAthentication (Au): NoneImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
Vulnerability Type: CWE-20 Vulnerability Consequences: Gain Access References: Source: MITRE Type: CNACVE-2012-2882 Source: CONFIRM Type: Vendor Advisoryhttp://googlechromereleases.blogspot.com/2012/09/stable-channel-update_25.html Source: CCN Type: Google Chrome Releases Blog, Tuesday, September 25, 2012 | 10:67Stable Channel Update 42 Source: SUSE Type: Third Party AdvisoryopenSUSE-SU-2012:1376 Source: CCN Type: SA50759Google Chrome Multiple Vulnerabilities Source: CCN Type: OSVDB ID: 85756Google Chrome OGG Container Handling Unspecified Invalid Pointer Dereference Source: CCN Type: BID-55676Google Chrome Prior to 22.0.1229.79 Multiple Security Vulnerabilities Source: CONFIRM Type: Issue Tracking, Patchhttps://chromiumcodereview.appspot.com/10829204 Source: CONFIRM Type: Issue Tracking, Patchhttps://code.google.com/p/chromium/issues/detail?id=140647 Source: XF Type: UNKNOWNgoogle-chrome-cve20122882(78839) Source: XF Type: UNKNOWNgoogle-chrome-cve20122882(78839) Source: OVAL Type: UNKNOWNoval:org.mitre.oval:def:15688 Source: CONFIRM Type: Issue Tracking, Patchhttps://src.chromium.org/viewvc/chrome?view=rev&revision=150239 Source: CCN Type: WhiteSource Vulnerability DatabaseCVE-2012-2882 Vulnerable Configuration: Configuration 1 :cpe:/a:google:chrome:22.0.1229.0:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.1:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.2:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.3:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.4:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.6:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.7:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.8:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.9:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.10:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.11:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.12:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.14:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.16:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.17:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.18:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.20:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.21:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.22:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.23:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.24:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.25:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.26:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.27:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.28:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.29:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.31:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.32:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.33:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.35:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.36:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.37:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.39:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.48:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.49:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.50:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.51:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.52:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.53:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.54:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.55:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.56:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.57:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.58:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.59:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.60:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.62:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.63:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.64:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.65:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.67:*:*:*:*:*:*:* OR cpe:/a:google:chrome:22.0.1229.76:*:*:*:*:*:*:* OR cpe:/a:google:chrome:*:*:*:*:*:*:*:* (Version <= 22.0.1229.78) Configuration 2 :cpe:/o:opensuse:opensuse:12.1:*:*:*:*:*:*:* OR cpe:/o:opensuse:opensuse:12.2:*:*:*:*:*:*:* Denotes that component is vulnerable Oval Definitions BACK
google chrome 22.0.1229.0
google chrome 22.0.1229.1
google chrome 22.0.1229.2
google chrome 22.0.1229.3
google chrome 22.0.1229.4
google chrome 22.0.1229.6
google chrome 22.0.1229.7
google chrome 22.0.1229.8
google chrome 22.0.1229.9
google chrome 22.0.1229.10
google chrome 22.0.1229.11
google chrome 22.0.1229.12
google chrome 22.0.1229.14
google chrome 22.0.1229.16
google chrome 22.0.1229.17
google chrome 22.0.1229.18
google chrome 22.0.1229.20
google chrome 22.0.1229.21
google chrome 22.0.1229.22
google chrome 22.0.1229.23
google chrome 22.0.1229.24
google chrome 22.0.1229.25
google chrome 22.0.1229.26
google chrome 22.0.1229.27
google chrome 22.0.1229.28
google chrome 22.0.1229.29
google chrome 22.0.1229.31
google chrome 22.0.1229.32
google chrome 22.0.1229.33
google chrome 22.0.1229.35
google chrome 22.0.1229.36
google chrome 22.0.1229.37
google chrome 22.0.1229.39
google chrome 22.0.1229.48
google chrome 22.0.1229.49
google chrome 22.0.1229.50
google chrome 22.0.1229.51
google chrome 22.0.1229.52
google chrome 22.0.1229.53
google chrome 22.0.1229.54
google chrome 22.0.1229.55
google chrome 22.0.1229.56
google chrome 22.0.1229.57
google chrome 22.0.1229.58
google chrome 22.0.1229.59
google chrome 22.0.1229.60
google chrome 22.0.1229.62
google chrome 22.0.1229.63
google chrome 22.0.1229.64
google chrome 22.0.1229.65
google chrome 22.0.1229.67
google chrome 22.0.1229.76
google chrome *
opensuse opensuse 12.1
opensuse opensuse 12.2