Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:47390
HistoryJun 06, 2024 - 7:31 a.m.

Integer Overflow

2024-06-0607:31:15
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
libvpx.so
integer overflow
vulnerability
buffer sizes
software

5.9 Medium

CVSS4

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

PASSIVE

CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:L/SC:L/VI:H/SI:L/VA:N/SA:N

6.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.2%

libvpx.so is vulnerable to Integer Overflow. The vulnerability is caused by calling large values of the d_w, d_h, or align parameter in the functions vpx_img_alloc() and vpx_img_wrap(), leading to invalid buffer sizes and offsets.

5.9 Medium

CVSS4

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

PASSIVE

CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:L/SC:L/VI:H/SI:L/VA:N/SA:N

6.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.2%