In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112001302
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libvpx | Aug 22, 2024 | Sep 27, 2019 |
| Debian | — | Upgrade libvpx | Dec 2, 2019 | Sep 27, 2019 |
| Gentoo Linux | — | Upgrade media-libs/libvpx. | Mar 27, 2020 | Sep 27, 2019 |
| Oracle Solaris | — | Upgrade web/browser/firefox to version 68.9.0-11.4.24.0.1.75.1 on Solaris 11.4Upgrade mail/thunderbird to version 68.9.0-11.4.24.0.1.75.1 on Solaris 11.4 | Jan 19, 2021 | Sep 27, 2019 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 27, 2019 |
| Suse | — | Upgrade vpx-toolsUpgrade libvpx4-32bitUpgrade libvpx4Upgrade libvpx-devel | Jan 21, 2020 | Sep 27, 2019 |
| Ubuntu | — | Upgrade libvpx5Upgrade libvpx3 | Nov 26, 2019 | Sep 27, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub