First published: Wed Jul 15 2020(Updated: )
USN-4199-1 fixed several vulnerabilities in libvpx. This update provides the corresponding update for Ubuntu 14.04 ESM. Original advisory details: It was discovered that libvpx did not properly handle certain malformed WebM media files. If an application using libvpx opened a specially crafted WebM file, a remote attacker could cause a denial of service, or possibly execute arbitrary code.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libvpx1 | <1.3.0-2ubuntu0.1~esm1 | 1.3.0-2ubuntu0.1~esm1 |
Ubuntu Linux | =14.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
USN-4199-2 addresses high-severity vulnerabilities in libvpx that could allow for potential application crashes or system security risks.
To fix USN-4199-2, update libvpx to version 1.3.0-2ubuntu0.1~esm1 on Ubuntu 14.04.
USN-4199-2 affects the libvpx package on Ubuntu 14.04.
USN-4199-2 addresses vulnerabilities related to improper handling of malformed WebM media files.
Yes, vulnerabilities addressed by USN-4199-2 can potentially be exploited through malformed media files processed by applications using libvpx.