[ALAS-2018-981] Amazon Linux AMI 2014.03 - ALAS-2018-981: critical priority package update for libvorbis

Severity Critical
Affected Packages 7
CVEs 1

Package updates are available for Amazon Linux AMI that fix the following vulnerabilities:
CVE-2018-5146:
An out of bounds write flaw was found in the processing of vorbis audio data. A maliciously crafted file or audio stream could cause the application to crash or, potentially, execute arbitrary code.
1557221:
CVE-2018-5146 Mozilla: Vorbis audio processing out of bounds write (MFSA 2018-08)

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/amazonlinux/libvorbis?arch=x86_64&distro=amazonlinux-1 amazonlinux libvorbis < 1.3.3-8.7.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/libvorbis?arch=i686&distro=amazonlinux-1 amazonlinux libvorbis < 1.3.3-8.7.amzn1 amazonlinux-1 i686
Affected pkg:rpm/amazonlinux/libvorbis-devel?arch=x86_64&distro=amazonlinux-1 amazonlinux libvorbis-devel < 1.3.3-8.7.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/libvorbis-devel?arch=i686&distro=amazonlinux-1 amazonlinux libvorbis-devel < 1.3.3-8.7.amzn1 amazonlinux-1 i686
Affected pkg:rpm/amazonlinux/libvorbis-devel-docs?arch=noarch&distro=amazonlinux-1 amazonlinux libvorbis-devel-docs < 1.3.3-8.7.amzn1 amazonlinux-1 noarch
Affected pkg:rpm/amazonlinux/libvorbis-debuginfo?arch=x86_64&distro=amazonlinux-1 amazonlinux libvorbis-debuginfo < 1.3.3-8.7.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/libvorbis-debuginfo?arch=i686&distro=amazonlinux-1 amazonlinux libvorbis-debuginfo < 1.3.3-8.7.amzn1 amazonlinux-1 i686
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...