First published: Thu Jan 22 2015(Updated: )
Use-after-free vulnerability in the matroska_read_seek function in libavformat/matroskadec.c in FFmpeg before 2.5.1, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted Matroska file that triggers improper maintenance of tracks data.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome | <=40.0.2214.85 | |
FFmpeg | <=2.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-7933 is classified as a high severity vulnerability due to its potential to cause denial of service and other unspecified impacts.
To remedy CVE-2014-7933, upgrade FFmpeg to version 2.5.1 or later and ensure Google Chrome is updated to version 40.0.2214.91 or higher.
CVE-2014-7933 affects FFmpeg versions before 2.5.1 and Google Chrome versions before 40.0.2214.91.
Yes, CVE-2014-7933 can be exploited by remote attackers via a crafted Matroska file.
CVE-2014-7933 is a use-after-free vulnerability that can lead to denial of service.