CVE-2012-5144: Canonical Ubuntu Linux

High severity, CVSS 10.0. EPSS: 3.4% chance of exploitation in the next 30 days.

Google Chrome before 23.0.1271.97, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.5, do not properly perform AAC decoding, which allows remote attackers to cause a denial of service (stack memory corruption) or possibly have unspecified other impact via vectors related to "an off-by-one overwrite when switching to LTP profile from MAIN."

Affected products

  • Canonical Ubuntu Linux: version 11.10 only; version 12.04 only; version 12.10 only
  • Google Chrome: up to and including 23.0.1271.96; version 23.0.1271.0 only; version 23.0.1271.1 only; version 23.0.1271.2 only; version 23.0.1271.3 only; version 23.0.1271.4 only; …
  • Libav Libav: version 0.8 only; version 0.8.1 only; version 0.8.2 only; version 0.8.3 only; version 0.8.4 only; version 0.7 only; …
  • Opensuse Opensuse: version 12.1 only; version 12.2 only

Published 2012-12-12. Last modified 2026-06-16.