In vp8_decode_frame of decodeframe.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure if error correction were turned on, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1Android ID: A-62458770
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libvpx | Aug 22, 2024 | Mar 10, 2020 |
| Amazon Linux Ami 2 | — | Upgrade libvpx-utilsUpgrade libvpx-debuginfoUpgrade libvpx-develUpgrade libvpx | Nov 12, 2020 | Mar 10, 2020 |
| Centos_linux | — | Upgrade libvpxUpgrade libvpx-utilsUpgrade libvpx-debuginfoUpgrade libvpx-devel | Oct 1, 2020 | Mar 10, 2020 |
| Debian | — | Upgrade libvpx | Mar 11, 2020 | Mar 11, 2020 |
| Huawei Euleros 2_0_sp2 | — | Upgrade libvpx | Nov 3, 2020 | Mar 10, 2020 |
| Huawei Euleros 2_0_sp3 | — | Upgrade libvpx | Sep 28, 2020 | Mar 10, 2020 |
| Oracle_linux | — | Upgrade libvpxUpgrade libvpx-utilsUpgrade libvpx-devel | Oct 7, 2020 | Mar 2, 2020 |
| Redhat_linux | — | Upgrade libvpx-debuginfoUpgrade libvpx-utilsUpgrade libvpxUpgrade libvpx-develNo solution exists | Oct 1, 2020 | Mar 10, 2020 |
| Suse | — | Upgrade libvpx1-32bitUpgrade vpx-toolsUpgrade libvpx-develUpgrade libvpx1Upgrade libvpx4-32bitUpgrade libvpx4Upgrade libvpx7 | May 23, 2020 | Mar 10, 2020 |
| Ubuntu | — | Upgrade libvpx1 (Ubuntu Pro)Upgrade libvpx3 (Ubuntu Pro) | Sep 27, 2022 | Mar 10, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub