CVE-2017-1000460

Description

In line libavcodec/h264dec.c:500 in libav(v13_dev0), ffmpeg(n3.4), chromium(56 prior Feb 13, 2017), the return value of init_get_bits is ignored and get_ue_golomb(&gb) is called on an uninitialized get_bits context, which causes a NULL deref exception.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.216

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in Google Chrome (x64) 56.0.2924Windows
Multiple vulnerabilities affected in Google Chrome 56.0.2924Windows
Multiple vulnerabilities affected in Google Chrome 56.0.2924 (For Debian)Linux
Multiple vulnerabilities affected in Google Chrome 56.0.2924 (For Centos)Linux
Multiple vulnerabilities affected in Google Chrome 56.0.2924 (For RedHat)Linux
Multiple vulnerabilities affected in Google Chrome 56.0.2924 (For Suse)Linux
Multiple vulnerabilities affected in Google Chrome 56.0.2924 (For Ubuntu)Linux

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-343228Google Chrome (x64) (131.0.6778.85, 131.0.6778.86)
PATCH-343227Google Chrome (131.0.6778.85, 131.0.6778.86)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234