There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. Calling vpx_img_wrap() with a large value of the d_w, d_h, or stride_align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. We recommend upgrading to version 1.14.1 or beyond
CVSS Details
- CVSS 4.0 Base Score: 5.9 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:L/VI:H/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 9.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | alma-upgrade-libvpxalma-upgrade-libvpx-devel | Aug 30, 2024 | Jun 3, 2024 | |
| Alpine Linux | alpine-linux-upgrade-libvpx | Aug 22, 2024 | Jun 3, 2024 | |
| Amazon Linux Ami 2 | amazon-linux-ami-2-upgrade-firefoxamazon-linux-ami-2-upgrade-firefox-debuginfoamazon-linux-ami-2-upgrade-libvpxamazon-linux-ami-2-upgrade-libvpx-debuginfoamazon-linux-ami-2-upgrade-libvpx-develamazon-linux-ami-2-upgrade-libvpx-utilsamazon-linux-ami-2-upgrade-thunderbird | Aug 22, 2024 | Jun 3, 2024 | |
| Amazon_linux_2023 | amazon-linux-2023-upgrade-libvpxamazon-linux-2023-upgrade-libvpx-debuginfoamazon-linux-2023-upgrade-libvpx-debugsourceamazon-linux-2023-upgrade-libvpx-develamazon-linux-2023-upgrade-libvpx-utilsamazon-linux-2023-upgrade-libvpx-utils-debuginfo | Sep 30, 2025 | Jun 4, 2024 | |
| Debian | debian-upgrade-libvpx | Jun 18, 2024 | Jun 3, 2024 | |
| Oracle_linux | — | oracle-linux-upgrade-libvpxoracle-linux-upgrade-libvpx-devel | Oct 16, 2024 | Jun 4, 2024 |
| Redhat_linux | redhat-upgrade-libvpxredhat-upgrade-libvpx-debuginforedhat-upgrade-libvpx-debugsourceredhat-upgrade-libvpx-develredhat-upgrade-libvpx-utils-debuginfo | Sep 13, 2024 | Jun 3, 2024 | |
| Rocky_linux | rocky-upgrade-libvpxrocky-upgrade-libvpx-debuginforocky-upgrade-libvpx-debugsourcerocky-upgrade-libvpx-devel | Sep 17, 2024 | Jun 3, 2024 | |
| Suse | — | suse-upgrade-libvpx-develsuse-upgrade-libvpx4suse-upgrade-libvpx7suse-upgrade-libvpx7-32bitsuse-upgrade-libvpx9suse-upgrade-vpx-tools | Jul 12, 2024 | Jun 3, 2024 |
| Ubuntu | ubuntu-pro-upgrade-libvpx1ubuntu-pro-upgrade-libvpx3ubuntu-pro-upgrade-libvpx5ubuntu-pro-upgrade-vpx-toolsubuntu-upgrade-libvpx6ubuntu-upgrade-libvpx7ubuntu-upgrade-libvpx9 | Jun 7, 2024 | Jun 3, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub