DescriptionGoogle Chrome before 43.0.2357.65 relies on libvpx code that was not built with an appropriate --size-limit value, which allows remote attackers to trigger a negative value for a size field, and consequently cause a denial of service or possibly have unspecified other impact, via a crafted frame size in VP9 video data.
Overall state of this security issue: Does not affect SUSE products
This issue is currently rated as having moderate severity.
|National Vulnerability Database|
- openSUSE-SU-2015:0969-1, published Fri, 29 May 2015 17:06:19 +0200 (CEST)
- openSUSE-SU-2015:1877-1, published Mon, 2 Nov 2015 16:36:06 +0100 (CET)
List of released packages
|Product(s)||Fixed package version(s)||References|
|openSUSE 13.1|| ||Patchnames:
|openSUSE Leap 15.0|| ||Patchnames:
openSUSE Leap 15.0 GA chromium
|openSUSE Tumbleweed|| ||Patchnames:
openSUSE Tumbleweed GA chromedriver