Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2020:0105-1

Опубликовано: 25 янв. 2020
Источник: suse-cvrf

Описание

Security update for libvpx

This update for libvpx fixes the following issues:

  • CVE-2019-2126: Fixed a double free in ParseContentEncodingEntry() (bsc#1160611).
  • CVE-2019-9325: Fixed an out-of-bounds read (bsc#1160612).
  • CVE-2019-9232: Fixed an out-of-bounds memory access on fuzzed data (bsc#1160613).
  • CVE-2019-9433: Fixed a use-after-free in vp8_deblock() (bsc#1160614).
  • CVE-2019-9371: Fixed a resource exhaustion after memory leak (bsc#1160615).

This update was imported from the SUSE:SLE-15:Update update project.

Список пакетов

openSUSE Leap 15.1
libvpx-devel-1.6.1-lp151.5.3.1
libvpx4-1.6.1-lp151.5.3.1
libvpx4-32bit-1.6.1-lp151.5.3.1
vpx-tools-1.6.1-lp151.5.3.1

Описание

In ParseContentEncodingEntry of mkvparser.cc, there is a possible double free due to a missing reset of a freed pointer. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-127702368.


Затронутые продукты
openSUSE Leap 15.1:libvpx-devel-1.6.1-lp151.5.3.1
openSUSE Leap 15.1:libvpx4-1.6.1-lp151.5.3.1
openSUSE Leap 15.1:libvpx4-32bit-1.6.1-lp151.5.3.1
openSUSE Leap 15.1:vpx-tools-1.6.1-lp151.5.3.1

Ссылки

Описание

In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-122675483


Затронутые продукты
openSUSE Leap 15.1:libvpx-devel-1.6.1-lp151.5.3.1
openSUSE Leap 15.1:libvpx4-1.6.1-lp151.5.3.1
openSUSE Leap 15.1:libvpx4-32bit-1.6.1-lp151.5.3.1
openSUSE Leap 15.1:vpx-tools-1.6.1-lp151.5.3.1

Ссылки

Описание

In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112001302


Затронутые продукты
openSUSE Leap 15.1:libvpx-devel-1.6.1-lp151.5.3.1
openSUSE Leap 15.1:libvpx4-1.6.1-lp151.5.3.1
openSUSE Leap 15.1:libvpx4-32bit-1.6.1-lp151.5.3.1
openSUSE Leap 15.1:vpx-tools-1.6.1-lp151.5.3.1

Ссылки

Описание

In libvpx, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-132783254


Затронутые продукты
openSUSE Leap 15.1:libvpx-devel-1.6.1-lp151.5.3.1
openSUSE Leap 15.1:libvpx4-1.6.1-lp151.5.3.1
openSUSE Leap 15.1:libvpx4-32bit-1.6.1-lp151.5.3.1
openSUSE Leap 15.1:vpx-tools-1.6.1-lp151.5.3.1

Ссылки

Описание

In libvpx, there is a possible information disclosure due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-80479354


Затронутые продукты
openSUSE Leap 15.1:libvpx-devel-1.6.1-lp151.5.3.1
openSUSE Leap 15.1:libvpx4-1.6.1-lp151.5.3.1
openSUSE Leap 15.1:libvpx4-32bit-1.6.1-lp151.5.3.1
openSUSE Leap 15.1:vpx-tools-1.6.1-lp151.5.3.1

Ссылки
Уязвимость openSUSE-SU-2020:0105-1