[USN-6403-3] libvpx vulnerabilities

Severity High
Affected Packages 4
CVEs 2

Several security issues were fixed in libvpx.

USN-6403-1 fixed several vulnerabilities in libvpx. This update provides
the corresponding update for Ubuntu 16.04 LTS.

Original advisory details:

It was discovered that libvpx did not properly handle certain malformed
media files. If an application using libvpx opened a specially crafted
file, a remote attacker could cause a denial of service, or possibly
execute arbitrary code.

Package Affected Version
pkg:deb/ubuntu/vpx-tools?distro=xenial < 1.5.0-2ubuntu1.1+esm2
pkg:deb/ubuntu/libvpx3?distro=xenial < 1.5.0-2ubuntu1.1+esm2
pkg:deb/ubuntu/libvpx-doc?distro=xenial < 1.5.0-2ubuntu1.1+esm2
pkg:deb/ubuntu/libvpx-dev?distro=xenial < 1.5.0-2ubuntu1.1+esm2
ID
USN-6403-3
Severity
high
Severity from
CVE-2023-5217
URL
https://ubuntu.com/security/notices/USN-6403-3
Published
2023-11-01T09:29:41
(10 months ago)
Modified
2023-11-01T09:29:41
(10 months ago)
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:deb/ubuntu/vpx-tools?distro=xenial ubuntu vpx-tools < 1.5.0-2ubuntu1.1+esm2 xenial
Affected pkg:deb/ubuntu/libvpx3?distro=xenial ubuntu libvpx3 < 1.5.0-2ubuntu1.1+esm2 xenial
Affected pkg:deb/ubuntu/libvpx-doc?distro=xenial ubuntu libvpx-doc < 1.5.0-2ubuntu1.1+esm2 xenial
Affected pkg:deb/ubuntu/libvpx-dev?distro=xenial ubuntu libvpx-dev < 1.5.0-2ubuntu1.1+esm2 xenial
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...