CVE-2013-0899: Google Chrome
Medium severity, CVSS 5.0. EPSS: 1.5% chance of exploitation in the next 30 days.
Integer overflow in the padding implementation in the opus_packet_parse_impl function in src/opus_decoder.c in Opus before 1.0.2, as used in Google Chrome before 25.0.1364.97 on Windows and Linux and before 25.0.1364.99 on Mac OS X and other products, allows remote attackers to cause a denial of service (out-of-bounds read) via a long packet.
Affected products
- Google Chrome: before 25.0.1364.97 (fixed in 25.0.1364.97); before 25.0.1364.99 (fixed in 25.0.1364.99)
- Opensuse Opensuse: version 12.1 only; version 12.2 only
- Opus-Codec Opus: before 1.0.2 (fixed in 1.0.2)
Published 2013-02-23. Last modified 2026-06-16.