CVE-2014-7933

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Use-after-free vulnerability in the matroska_read_seek function in libavformat/matroskadec.c in FFmpeg before 2.5.1, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted Matroska file that triggers improper maintenance of tracks data.

References

http://git.videolan.org/?p=ffmpeg.git;a=commit;h=490a3ebf36821b81f73e34ad3f554cb523dd2682

http://googlechromereleases.blogspot.com/2015/01/stable-update.html

http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00005.html

http://rhn.redhat.com/errata/RHSA-2015-0093.html

http://secunia.com/advisories/62383

http://secunia.com/advisories/62575

http://secunia.com/advisories/62665

http://security.gentoo.org/glsa/glsa-201502-13.xml

http://www.securityfocus.com/bid/72288

http://www.securitytracker.com/id/1031623

http://www.ubuntu.com/usn/USN-2476-1

https://code.google.com/p/chromium/issues/detail?id=427266

Details

Source: MITRE

Published: 2015-01-22

Updated: 2017-01-03

Risk Information

CVSS v2

Base Score: 7.5

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 10

Severity: HIGH

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* versions up to 40.0.2214.85 (inclusive)

Configuration 2

OR

cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:* versions up to 2.5.0 (inclusive)

Tenable Plugins

View all (9 total)

IDNameProductFamilySeverity
81833Debian DSA-3189-1 : libav - security updateNessusDebian Local Security Checks
high
81692openSUSE Security Update : chromium (openSUSE-2015-204)NessusSuSE Local Security Checks
high
81396GLSA-201502-13 : Chromium: Multiple vulnerabilitiesNessusGentoo Local Security Checks
high
8889Google Chrome < 40.0.2214.91 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
high
81035RHEL 6 : chromium-browser (RHSA-2015:0093)NessusRed Hat Local Security Checks
high
81016Ubuntu 14.04 LTS / 14.10 : oxide-qt vulnerabilities (USN-2476-1)NessusUbuntu Local Security Checks
high
80951Google Chrome < 40.0.2214.91 Multiple VulnerabilitiesNessusWindows
high
80950Google Chrome < 40.0.2214.91 Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
high
80898FreeBSD : chromium -- multiple vulnerabilities (e30e0c99-a1b7-11e4-b85c-00262d5ed8ee)NessusFreeBSD Local Security Checks
high