First published: Mon Nov 25 2019(Updated: )
It was discovered that libvpx did not properly handle certain malformed WebM media files. If an application using libvpx opened a specially crafted WebM file, a remote attacker could cause a denial of service, or possibly execute arbitrary code.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libvpx5 | <1.7.0-3ubuntu0.19.04.1 | 1.7.0-3ubuntu0.19.04.1 |
Ubuntu Linux | =19.04 | |
All of | ||
ubuntu/libvpx5 | <1.7.0-3ubuntu0.18.04.1 | 1.7.0-3ubuntu0.18.04.1 |
Ubuntu Linux | =18.04 | |
All of | ||
ubuntu/libvpx3 | <1.5.0-2ubuntu1.1 | 1.5.0-2ubuntu1.1 |
Ubuntu Linux | =16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
The severity of USN-4199-1 is considered significant due to the potential for remote code execution and denial of service.
To fix USN-4199-1, update libvpx to version 1.7.0-3ubuntu0.19.04.1 for Ubuntu 19.04, 1.7.0-3ubuntu0.18.04.1 for Ubuntu 18.04, or 1.5.0-2ubuntu1.1 for Ubuntu 16.04.
Applications using libvpx that handle specific malformed WebM media files are affected by USN-4199-1.
USN-4199-1 addresses vulnerabilities that could lead to denial of service or arbitrary code execution through malformed WebM files.
USN-4199-1 was released to address vulnerabilities identified in libvpx that could be exploited by specially crafted media files.