INFSA-2024:9827: libvpx security update

Information about definition

Identificator: INFSA-2024:9827

Type: security

Release date: 2024-12-13 12:18:43 UTC

Information about package

The libvpx packages provide the VP8 SDK, which allows the encoding and decoding of the VP8 video codec, commonly used with the WebM multimedia container file format.

Vulnerabilities description

  • CVE-2024-5197

    A flaw was found in libvpx. When creating images, libvpx trusts the width, height, and alignment of the user input. However, it does not properly validate the provided values. This flaw allows an attacker to craft user inputs or trick the user into opening crafted files, where these types of values are invalid, leading to integer overflows during memory allocation procedures. A successful full attack leads to the targeted application crashing, resulting in a denial of service or memory corruption, which results in data integrity issues.

Severity level

CVE Score CVSS 2.0 Score CVSS 3.x Score CVSS 4.0
NIST — CVE-2024-5197
no information 7.1 no information
Critical, important, moderate, low

Updated packages