Red Hat Bugzilla – Bug 1547349
CVE-2018-6406 libwebm: Out of bounds read in libwebm_util.cc:ParseVP9SuperFrameIndex() can lead to information leak or potential denial of service
Last modified: 2018-03-01 02:07:58 EST
libwebm through versions 1.0.0.27, which is bundled in chromium, is vulnerable to an out of bounds read issue. The function common/libwebm_util.cc:ParseVP9SuperFrameIndex() does not validate child_frame_length data obtained from a .webm file, which can cause an information leak, denial of service or other potential unspecified impact. Upstream Commit: https://github.com/webmproject/libwebm/commit/8e88e04b07352f2ca449278b44a2d8ec7631bdcf
Created chromium tracking bugs for this issue: Affects: epel-7 [bug 1547350] Affects: fedora-all [bug 1547351]