Lucene search

K
redhatRedHatRHSA-2010:0999
HistoryDec 20, 2010 - 12:00 a.m.

(RHSA-2010:0999) Moderate: libvpx security update

2010-12-2000:00:00
access.redhat.com
20

EPSS

0.043

Percentile

92.3%

The libvpx packages provide the VP8 SDK, which allows the encoding and
decoding of the VP8 video codec, commonly used with the WebM multimedia
container file format.

An integer overflow flaw, leading to arbitrary memory writes, was found in
libvpx. An attacker could create a specially-crafted video encoded using
the VP8 codec that, when played by a victim with an application using
libvpx (such as Totem), would cause the application to crash or,
potentially, execute arbitrary code. (CVE-2010-4203)

All users of libvpx are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
update, all applications using libvpx must be restarted for the changes to
take effect.