CVE Vulnerabilities

CVE-2014-7933

Published: Jan 22, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
6.8 IMPORTANT
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Use-after-free vulnerability in the matroska_read_seek function in libavformat/matroskadec.c in FFmpeg before 2.5.1, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted Matroska file that triggers improper maintenance of tracks data.

Affected Software

NameVendorStart VersionEnd Version
ChromeGoogle*40.0.2214.85 (including)
Supplementary for Red Hat Enterprise Linux 6RedHatchromium-browser-0:40.0.2214.91-1.el6_6*
Chromium-browserUbuntuartful*
Chromium-browserUbuntubionic*
Chromium-browserUbuntudevel*
Chromium-browserUbuntulucid*
Chromium-browserUbuntuprecise*
Chromium-browserUbuntutrusty*
Chromium-browserUbuntuupstream*
Chromium-browserUbuntuutopic*
Chromium-browserUbuntuvivid*
Chromium-browserUbuntuwily*
Chromium-browserUbuntuxenial*
Chromium-browserUbuntuyakkety*
Chromium-browserUbuntuzesty*
FfmpegUbuntulucid*
LibavUbuntuesm-infra-legacy/trusty*
LibavUbuntuprecise*
LibavUbuntutrusty*
LibavUbuntutrusty/esm*
LibavUbuntuupstream*
LibavUbuntuutopic*
LibavUbuntuvivid*
MplayerUbuntuartful*
MplayerUbuntulucid*
MplayerUbuntuprecise*
MplayerUbuntuyakkety*
MplayerUbuntuzesty*
Oxide-qtUbuntuartful*
Oxide-qtUbuntuesm-infra/xenial*
Oxide-qtUbuntutrusty*
Oxide-qtUbuntuupstream*
Oxide-qtUbuntuutopic*
Oxide-qtUbuntuvivid*
Oxide-qtUbuntuvivid/stable-phone-overlay*
Oxide-qtUbuntuwily*
Oxide-qtUbuntuxenial*
Oxide-qtUbuntuyakkety*
Oxide-qtUbuntuzesty*

References