CVE-2013-0899: Google Chrome

Medium severity, CVSS 5.0. EPSS: 1.5% chance of exploitation in the next 30 days.

Integer overflow in the padding implementation in the opus_packet_parse_impl function in src/opus_decoder.c in Opus before 1.0.2, as used in Google Chrome before 25.0.1364.97 on Windows and Linux and before 25.0.1364.99 on Mac OS X and other products, allows remote attackers to cause a denial of service (out-of-bounds read) via a long packet.

Affected products

  • Google Chrome: before 25.0.1364.97 (fixed in 25.0.1364.97); before 25.0.1364.99 (fixed in 25.0.1364.99)
  • Opensuse Opensuse: version 12.1 only; version 12.2 only
  • Opus-Codec Opus: before 1.0.2 (fixed in 1.0.2)

Published 2013-02-23. Last modified 2026-06-16.