CVE-2012-2849
Off-by-one error in the GIF decoder in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image.
- Affected products
- Chrome Frame, Google Chrome, Linux, Macos X, Windows
- Google Chrome
- ≤ 21.0.1180.56, 21.0.1180.0, 21.0.1180.1, 21.0.1180.2, 21.0.1180.31, 21.0.1180.32, 21.0.1180.33, 21.0.1180.34, 21.0.1180.35, 21.0.1180.36, 21.0.1180.37, 21.0.1180.38, 21.0.1180.39, 21.0.1180.41, 21.0.1180.46, 21.0.1180.47, 21.0.1180.48, 21.0.1180.49, 21.0.1180.50, 21.0.1180.51, 21.0.1180.52, 21.0.1180.53, 21.0.1180.54, 21.0.1180.55
- CVSS 2.0
- 4.3 MEDIUM
- EPSS
- 1.2% (65th percentile)
- Weakness
- CWE-189
- NVD status
- Modified
- Published
- 2012-08-06
CVE-2012-2849 at NVD
1 known exploit for CVE-2012-2849
Proof-of-concept code and exploit modules indexed by Sploitus