[GLSA-202310-04] libvpx: Multiple Vulnerabilities

Severity High
Affected Packages 1
Unaffected Packages 1
CVEs 2

Multiple vulnerabilities have been discovered in libvpx, the worst of which could result in arbitrary code execution.

Background
libvpx is the VP8 codec SDK used to encode and decode video streams, typically within a WebM format media file.

Description
Multiple vulnerabilities have been discovered in libvpx. Please review the CVE identifiers referenced below for details.

Impact
Please review the referenced CVE identifiers for details.

Workaround
There is no known workaround at this time.

Resolution
All libvpx users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=media-libs/libvpx-1.13.1"

Package Affected Version
pkg:ebuild/media-libs/libvpx?distro=gentoo < 1.13.1
Package Unaffected Version
pkg:ebuild/media-libs/libvpx?distro=gentoo >= 1.13.1
ID
GLSA-202310-04
Severity
high
URL
https://security.gentoo.org/glsa/202310-04
Published
2023-10-04T00:00:00
(11 months ago)
Modified
2023-10-04T00:00:00
(11 months ago)
Rights
Gentoo Foundation, Inc.
Other Advisories
Source # ID Name URL
CVE CVE-2023-5217 CVE-2023-5217 https://nvd.nist.gov/vuln/detail/CVE-2023-5217
CVE CVE-2023-44488 CVE-2023-44488 https://nvd.nist.gov/vuln/detail/CVE-2023-44488
Bugzilla 914875 Bugzilla #914875 https://bugs.gentoo.org/show_bug.cgi?id=914875
Bugzilla 914987 Bugzilla #914987 https://bugs.gentoo.org/show_bug.cgi?id=914987
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:ebuild/media-libs/libvpx?distro=gentoo media-libs libvpx < 1.13.1 gentoo
Unaffected pkg:ebuild/media-libs/libvpx?distro=gentoo media-libs libvpx >= 1.13.1 gentoo
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...