DescriptionA use-after-free issue was discovered in libwebm through 2018-02-02. If a Vp9HeaderParser was initialized once before, its property frame_ would not be changed because of code in vp9parser::Vp9HeaderParser::SetFrame. Its frame_ could be freed while the corresponding pointer would not be updated, leading to a dangling pointer. This is related to the function OutputCluster in
Vulnerable and fixed packages

The table below lists information on source packages.

Source Package Release Version Status
chromium-browser (PTS)jessie, jessie (lts)57.0.2987.98-1~deb8u1vulnerable
stretch (security), stretch (lts), stretch71.0.3578.80-1~deb9u1vulnerable

The information below is based on the following data on fixed versions.

Package Type Release Fixed Version Urgency Origin Debian Bugs


Chromium is built with support for VP9 disabled in Debian

