CVE-2015-8480: Buffer Overflow
The VideoFramePool::PoolImpl::CreateFrame function in media/base/videoframepool.cc in Google Chrome before 47.0.2526.73 does not initialize memory for a video-frame data structure, which might allow remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact by leveraging improper interaction with the vp3hloopfilterc function in libavcodec/vp3dsp.c in FFmpeg.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8480?
CVE-2015-8480 is considered a moderate severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2015-8480?
To fix CVE-2015-8480, upgrade Google Chrome to version 47.0.2526.73 or later.
What type of attack can exploit CVE-2015-8480?
CVE-2015-8480 can be exploited by remote attackers to cause denial of service through out-of-bounds memory access.
Which versions of Google Chrome are affected by CVE-2015-8480?
Google Chrome versions before 47.0.2526.73 are affected by CVE-2015-8480.
Is user intervention required to exploit CVE-2015-8480?
Exploitation of CVE-2015-8480 can occur without user intervention, potentially affecting users who visit malicious websites.