Lucene search

K
ubuntuUbuntuUSN-6814-1
HistoryJun 06, 2024 - 12:00 a.m.

libvpx vulnerability

2024-06-0600:00:00
ubuntu.com
1
ubuntu
libvpx
security
media files
denial of service
arbitrary code
vulnerability

5.9 Medium

CVSS4

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

PASSIVE

CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:L/SC:L/VI:H/SI:L/VA:N/SA:N

7.5 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.2%

Releases

  • Ubuntu 24.04 LTS
  • Ubuntu 23.10
  • Ubuntu 22.04 LTS
  • Ubuntu 20.04 LTS

Packages

  • libvpx - VP8 and VP9 video codec

Details

Xiantong Hou discovered that libvpx did not properly handle certain
malformed media files. If an application using libvpx opened a specially
crafted file, a remote attacker could cause a denial of service, or
possibly execute arbitrary code.

OSVersionArchitecturePackageVersionFilename
Ubuntu24.04noarchlibvpx9< 1.14.0-1ubuntu2.1UNKNOWN
Ubuntu24.04noarchlibvpx-dev< 1.14.0-1ubuntu2.1UNKNOWN
Ubuntu24.04noarchlibvpx-doc< 1.14.0-1ubuntu2.1UNKNOWN
Ubuntu24.04noarchlibvpx9-dbgsym< 1.14.0-1ubuntu2.1UNKNOWN
Ubuntu24.04noarchvpx-tools< 1.14.0-1ubuntu2.1UNKNOWN
Ubuntu24.04noarchvpx-tools-dbgsym< 1.14.0-1ubuntu2.1UNKNOWN
Ubuntu23.10noarchlibvpx7< 1.12.0-1ubuntu2.1UNKNOWN
Ubuntu23.10noarchlibvpx-dev< 1.12.0-1ubuntu2.1UNKNOWN
Ubuntu23.10noarchlibvpx-doc< 1.12.0-1ubuntu2.1UNKNOWN
Ubuntu23.10noarchlibvpx7-dbgsym< 1.12.0-1ubuntu2.1UNKNOWN
Rows per page:
1-10 of 241

5.9 Medium

CVSS4

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

PASSIVE

CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:L/SC:L/VI:H/SI:L/VA:N/SA:N

7.5 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.2%