Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2020-3876

Опубликовано: 06 окт. 2020
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2020-3876: libvpx security update (MODERATE)

[1.3.0-8]

  • Fix for CVE-2020-0034
  • Resolves: rhbz#1823909

[1.3.0-7]

  • Fix for CVE-2019-9232 and CVE-2019-9433
  • Resolves: rhbz#1796085, rhbz#1796099

[1.3.0-6]

  • Fix for CVE-2017-0393
  • Resolves: rhbz#1779498

[1.3.0-4]

  • fix Illegal Instruction abort

[1.3.0-3]

  • update library symbol list for 1.3.0 from Debian

[1.3.0-2]

  • armv7hl specific target

[1.3.0-1]

  • update to 1.3.0

[1.2.0-1]

  • update to 1.2.0

[1.1.0-1]

  • update to 1.1.0

[1.0.0-3]

  • fix vpx.pc file to include -lm (bz825754)

[1.0.0-2]

  • use included vpx.pc file (drop local libvpx.pc)
  • apply upstream fix to vpx.pc file (bz 814177)

[1.0.0-1]

  • update to 1.0.0

[0.9.7.1-3]

  • use macro instead of hard-coded version

[0.9.7.1-2]

  • fix build on generic targets

[0.9.7.1-1]

  • libvpx 0.9.7-p1

[0.9.7-1]

  • libvpx 0.9.7

[0.9.6-2]

  • add 2 symbols to the shared library for generic targets

[0.9.6-1]

  • update to 0.9.6

[0.9.5-3]

[0.9.5-2]

  • apply patch from upstream git (Change I6266aba7), should resolve CVE-2010-4203

[0.9.5-1]

  • update to 0.9.5

[0.9.1-3]

  • only package html docs to avoid multilib conflict (bz 613185)

[0.9.1-2]

  • build shared library the old way for generic arches

[0.9.1-1]

  • update to 0.9.1

[0.9.0-7]

  • update to git revision 8389f1967c5f8b3819cca80705b1b4ba04132b93
  • upstream fix for bz 599147
  • proper shared library support

[0.9.0-6]

  • add hackish fix for bz 599147 (upstream will hopefully fix properly in future release)

[0.9.0-5]

  • fix noexecstack flag

[0.9.0-4]

  • BuildRequires: yasm (were optimized again)

[0.9.0-3]

  • add pkg-config file
  • move headers into include/vpx/
  • enable optimization

[0.9.0-2]

  • fix permissions on binaries
  • rename generic binaries to v8_*
  • link shared library to -lm, -lpthread to resolve missing weak symbols

[0.9.0-1]

  • Initial package for Fedora

Обновленные пакеты

Oracle Linux 7

Oracle Linux aarch64

libvpx

1.3.0-8.el7

libvpx-devel

1.3.0-8.el7

libvpx-utils

1.3.0-8.el7

Oracle Linux x86_64

libvpx

1.3.0-8.el7

libvpx-devel

1.3.0-8.el7

libvpx-utils

1.3.0-8.el7

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 8 лет назад

A denial of service vulnerability in libvpx in Mediaserver could enable a remote attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-30436808.

CVSS3: 5.5
redhat
больше 8 лет назад

A denial of service vulnerability in libvpx in Mediaserver could enable a remote attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-30436808.

CVSS3: 5.5
nvd
больше 8 лет назад

A denial of service vulnerability in libvpx in Mediaserver could enable a remote attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-30436808.

CVSS3: 5.5
debian
больше 8 лет назад

A denial of service vulnerability in libvpx in Mediaserver could enabl ...

CVSS3: 5.5
github
около 3 лет назад

A denial of service vulnerability in libvpx in Mediaserver could enable a remote attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-30436808.