CVE-2012-5144
Publication date 12 December 2012
Last updated 24 July 2024
Ubuntu priority
Google Chrome before 23.0.1271.97, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.5, do not properly perform AAC decoding, which allows remote attackers to cause a denial of service (stack memory corruption) or possibly have unspecified other impact via vectors related to “an off-by-one overwrite when switching to LTP profile from MAIN.”
Status
Package | Ubuntu Release | Status |
---|---|---|
chromium-browser | 12.10 quantal |
Fixed 3.0.1271.97-0ubuntu0.12.10.1
|
12.04 LTS precise |
Fixed 3.0.1271.97-0ubuntu0.12.04.1
|
|
11.10 oneiric |
Fixed 3.0.1271.97-0ubuntu0.11.10.1
|
|
10.04 LTS lucid |
Fixed 3.0.1271.97-0ubuntu0.10.04.1
|
|
8.04 LTS hardy | Not in release | |
ffmpeg | 12.10 quantal | Not in release |
12.04 LTS precise | Not in release | |
11.10 oneiric | Not in release | |
11.04 natty | Not in release | |
10.04 LTS lucid |
Not affected
|
|
8.04 LTS hardy | Ignored end of life | |
ffmpeg-extra | 12.10 quantal | Not in release |
12.04 LTS precise | Not in release | |
11.10 oneiric | Not in release | |
11.04 natty | Not in release | |
10.04 LTS lucid |
Not affected
|
|
8.04 LTS hardy | Not in release | |
libav | 12.10 quantal |
Fixed 6:0.8.5-0ubuntu0.12.10.1
|
12.04 LTS precise |
Fixed 4:0.8.5-0ubuntu0.12.04.1
|
|
11.10 oneiric |
Fixed 4:0.7.6-0ubuntu0.11.10.3
|
|
11.04 natty | Ignored end of life | |
10.04 LTS lucid | Not in release | |
8.04 LTS hardy | Not in release | |
libav-extra | 12.10 quantal |
Fixed 6:0.8.5ubuntu0.12.10.1
|
12.04 LTS precise |
Fixed 4:0.8.5ubuntu0.12.04.1
|
|
11.10 oneiric |
Fixed 4:0.7.6ubuntu0.11.10.3
|
|
11.04 natty | Ignored end of life | |
10.04 LTS lucid | Not in release | |
8.04 LTS hardy | Not in release |
Notes
Patch details
Package | Patch details |
---|---|
libav |
References
Related Ubuntu Security Notices (USN)
- USN-1705-1
- Libav vulnerabilities
- 28 January 2013