CVE-2013-0899 is an integer overflow vulnerability in the Opus codec, specifically within the padding implementation of the opus_packet_parse_impl function. This flaw, affecting Opus before version 1.0.2 and subsequently Google Chrome and other products, allows remote attackers to trigger a denial of service via an out-of-bounds read using a crafted, long packet. With a CVSS score of 5.0, it is considered a medium-severity vulnerability, requiring no authentication and having low attack complexity, though its impact is limited to availability. There is no evidence of active exploitation, and no public exploit code is available, despite some community discussion and media coverage at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.2CPE matchmatch criteria | cpe:2.3:a:opus-codec:opus:*:*:*:*:*:*:*:* | ||
< 25.0.1364.97CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 25.0.1364.99CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
12.1CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:12.1:*:*:*:*:*:*:* | ||
12.2CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:12.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.