Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-0034

Опубликовано: 02 мар. 2020
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

In vp8_decode_frame of decodeframe.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure if error correction were turned on, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1Android ID: A-62458770

Отчет

The version shipped with Red Hat Enterprse Linux 8 already contains the commit which fix this issue, thus this version is not affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libvpxOut of support scope
Red Hat Enterprise Linux 8libvpxNot affected
Red Hat Enterprise Linux 7libvpxFixedRHSA-2020:387629.09.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20->CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1813000libvpx: Out of bounds read in vp8_decode_frame in decodeframe.c

EPSS

Процентиль: 84%
0.02415
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 5 лет назад

In vp8_decode_frame of decodeframe.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure if error correction were turned on, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1Android ID: A-62458770

CVSS3: 7.5
nvd
больше 5 лет назад

In vp8_decode_frame of decodeframe.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure if error correction were turned on, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1Android ID: A-62458770

CVSS3: 7.5
debian
больше 5 лет назад

In vp8_decode_frame of decodeframe.c, there is a possible out of bound ...

suse-cvrf
около 5 лет назад

Security update for libvpx

suse-cvrf
больше 3 лет назад

Security update for libvpx

EPSS

Процентиль: 84%
0.02415
Низкий

7.5 High

CVSS3