CVSS4
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
PASSIVE
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:L/SC:L/VI:H/SI:L/VA:N/SA:N
AI Score
Confidence
High
Medium
Canonical Ubuntu
Xiantong Hou discovered that libvpx did not properly handle certain malformed media files. If an application using libvpx opened a specially crafted file, a remote attacker could cause a denial of service, or possibly execute arbitrary code. Update Instructions: Run sudo pro fix USN-6814-1
to fix the vulnerability. The problem can be corrected by updating your system to the following package versions: libvpx-dev – 1.8.2-1ubuntu0.3 libvpx-doc – 1.8.2-1ubuntu0.3 libvpx6 – 1.8.2-1ubuntu0.3 vpx-tools – 1.8.2-1ubuntu0.3 No subscription required
CVEs contained in this USN include: CVE-2024-5197.
Severity is medium unless otherwise noted.
Users of affected products are strongly encouraged to follow the mitigations below.
The Cloud Foundry project recommends upgrading the following releases:
2024-07-25: Initial vulnerability report published.
Vendor | Product | Version | CPE |
---|---|---|---|
cloudfoundry | cflinuxfs4 | * | cpe:2.3:a:cloudfoundry:cflinuxfs4:*:*:*:*:*:*:*:* |
cloudfoundry | cf-deployment | * | cpe:2.3:a:cloudfoundry:cf-deployment:*:*:*:*:*:*:*:* |