[USN-6403-2] libvpx vulnerabilities

Severity High
Affected Packages 4
CVEs 2

Several security issues were fixed in libvpx.

USN-6403-1 fixed several vulnerabilities in libvpx. This update provides
the corresponding update for Ubuntu 18.04 LTS.

Original advisory details:

It was discovered that libvpx did not properly handle certain malformed
media files. If an application using libvpx opened a specially crafted
file, a remote attacker could cause a denial of service, or possibly
execute arbitrary code.

Package Affected Version
pkg:deb/ubuntu/vpx-tools?distro=bionic < 1.7.0-3ubuntu0.18.04.1+esm1
pkg:deb/ubuntu/libvpx5?distro=bionic < 1.7.0-3ubuntu0.18.04.1+esm1
pkg:deb/ubuntu/libvpx-doc?distro=bionic < 1.7.0-3ubuntu0.18.04.1+esm1
pkg:deb/ubuntu/libvpx-dev?distro=bionic < 1.7.0-3ubuntu0.18.04.1+esm1
ID
USN-6403-2
Severity
high
Severity from
CVE-2023-5217
URL
https://ubuntu.com/security/notices/USN-6403-2
Published
2023-10-23T15:46:57
(11 months ago)
Modified
2023-10-23T15:46:57
(11 months ago)
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:deb/ubuntu/vpx-tools?distro=bionic ubuntu vpx-tools < 1.7.0-3ubuntu0.18.04.1+esm1 bionic
Affected pkg:deb/ubuntu/libvpx5?distro=bionic ubuntu libvpx5 < 1.7.0-3ubuntu0.18.04.1+esm1 bionic
Affected pkg:deb/ubuntu/libvpx-doc?distro=bionic ubuntu libvpx-doc < 1.7.0-3ubuntu0.18.04.1+esm1 bionic
Affected pkg:deb/ubuntu/libvpx-dev?distro=bionic ubuntu libvpx-dev < 1.7.0-3ubuntu0.18.04.1+esm1 bionic
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...