Buffer overflow in Google Chrome - CVE-2014-3157

 

Buffer overflow in Google Chrome - CVE-2014-3157

Published: June 11, 2014 / Updated: August 10, 2020


Vulnerability identifier: #VU41561
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-3157
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

Heap-based buffer overflow in the FFmpegVideoDecoder::GetVideoBuffer function in media/filters/ffmpeg_video_decoder.cc in Google Chrome before 35.0.1916.153 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging VideoFrame data structures that are too small for proper interaction with an underlying FFmpeg library.


Affected software

Google Chrome

How to mitigate CVE-2014-3157

Install update from vendor's website.


External References

Related Security Bulletins