FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2012-2882

This CVE name corresponds to:

Entered Topic
2012-09-26 chromium -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2012-2882
Phase Assigned(20120519)

Description

FFmpeg, as used in Google Chrome before 22.0.1229.79, does not properly handle OGG containers, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors, related to a "wild pointer" issue.

References

Source Reference
CONFIRM http://googlechromereleases.blogspot.com/2012/09/stable-channel-update_25.html
CONFIRM https://chromiumcodereview.appspot.com/10829204
CONFIRM https://code.google.com/p/chromium/issues/detail?id=140647
CONFIRM https://src.chromium.org/viewvc/chrome?view=rev&revision=150239
SUSE openSUSE-SU-2012:1376
OVAL oval:org.mitre.oval:def:15688
XF google-chrome-cve20122882(78839)