Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2024:5941

Опубликовано: 17 сент. 2024
Источник: rocky
Оценка: Moderate

Описание

Moderate: libvpx security update

The libvpx packages provide the VP8 SDK, which allows the encoding and decoding of the VP8 video codec, commonly used with the WebM multimedia container file format.

Security Fix(es):

  • libvpx: Heap buffer overflow related to VP9 encoding (CVE-2023-6349)

  • libvpx: Integer overflow in vpx_img_alloc() (CVE-2024-5197)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
libvpxx86_6411.el8_10libvpx-1.7.0-11.el8_10.x86_64.rpm

Показывать по

Связанные CVE

Связанные уязвимости

suse-cvrf
11 месяцев назад

Security update for libvpx

oracle-oval
10 месяцев назад

ELSA-2024-5941: libvpx security update (MODERATE)

suse-cvrf
11 месяцев назад

Security update for libvpx

CVSS3: 8.8
redos
11 месяцев назад

Множественные уязвимости libvpx

ubuntu
около 1 года назад

A heap overflow vulnerability exists in libvpx - Encoding a frame that has larger dimensions than the originally configured size with VP9 may result in a heap overflow in libvpx. We recommend upgrading to version 1.13.1 or above