Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-9371

Опубликовано: 27 сент. 2019
Источник: debian
EPSS Низкий

Описание

In libvpx, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-132783254

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libvpxfixed1.8.1-2package
libvpxfixed1.7.0-3+deb10u1busterpackage
libvpxignoredstretchpackage
libvpxnot-affectedjessiepackage

Примечания

  • Commits in libwebm:

  • https://chromium.googlesource.com/webm/libwebm/+/027a472efe49ff3a24be619442d2150658dbaaa0

  • https://chromium.googlesource.com/webm/libwebm/+/cb5a9477073cf7ae4a28356d6e3e5638aba78dc9

  • Sync to libvpx via:

  • https://github.com/webmproject/libvpx/commit/34d54b04e98dd0bac32e9aab0fbda0bf501bc742

  • https://github.com/webmproject/libvpx/commit/f00890eecdf8365ea125ac16769a83aa6b68792d

EPSS

Процентиль: 91%
0.0743
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 5 лет назад

In libvpx, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-132783254

CVSS3: 6.5
redhat
больше 5 лет назад

In libvpx, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-132783254

CVSS3: 6.5
nvd
больше 5 лет назад

In libvpx, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-132783254

CVSS3: 6.5
github
около 3 лет назад

In libvpx, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-132783254

CVSS3: 6.5
fstec
больше 5 лет назад

Уязвимость библиотеки мультимедиа libvpx, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 91%
0.0743
Низкий