Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-39616

Опубликовано: 29 авг. 2023
Источник: debian
EPSS Низкий

Описание

AOMedia v3.0.0 to v3.5.0 was discovered to contain an invalid read memory access via the component assign_frame_buffer_p in av1/common/av1_common_int.h.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
aomfixed3.7.0-1~exp1experimentalpackage
aomfixed3.7.0-1package
aomignoredbookwormpackage
aomnot-affectedbullseyepackage
aomnot-affectedbusterpackage

Примечания

  • https://bugs.chromium.org/p/aomedia/issues/detail?id=3372#c3

  • Introduced by: https://aomedia.googlesource.com/aom/+/55318e3c27fbcff4b4888e6b413ca1e34e4fb8a1 (3.4.0_rc1)

  • Fixed by: https://aomedia.googlesource.com/aom/+/35254736d9753447ac9bccf8e0062bdb74b0bdb7 (3.7.0_rc2)

  • Fixed by: https://aomedia.googlesource.com/aom/+/cbce06167ac7adc945786320ae3ea6e39b11e1d1 (3.7.0_rc2)

  • Fixed by: https://aomedia.googlesource.com/aom/+/54e4b8fffababa02c31674b3b37dc0c26dd0a898 (3.7.0_rc2)

  • Fixed by: https://aomedia.googlesource.com/aom/+/df38eb169193f169bb4a81edd7b54d15cd5afc2a (3.7.0_rc2)

  • Testcase: https://aomedia.googlesource.com/aom/+/7c3bcc8fa57ffda7f128f3cea9e8bb31c83fe4b7 (3.7.0_rc2)

  • Testcase: https://aomedia.googlesource.com/aom/+/d90659acbb1487949195006d46c4582c62f1b90f (3.7.0_rc2)

  • For Debian this was initially fixed in Debian unstable with 3.7.0~rc3-1 but reverted with the

  • 3.7.0~really3.6.1-1 upload re-introducing the issue.

EPSS

Процентиль: 21%
0.00068
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

AOMedia v3.0.0 to v3.5.0 was discovered to contain an invalid read memory access via the component assign_frame_buffer_p in av1/common/av1_common_int.h.

CVSS3: 7.5
nvd
больше 2 лет назад

AOMedia v3.0.0 to v3.5.0 was discovered to contain an invalid read memory access via the component assign_frame_buffer_p in av1/common/av1_common_int.h.

CVSS3: 7.5
github
больше 2 лет назад

AOMedia v3.0.0 to v3.5.0 was discovered to contain an invalid read memory access via the component assign_frame_buffer_p in av1/common/av1_common_int.h.

EPSS

Процентиль: 21%
0.00068
Низкий