USN-7172-1: libvpx vulnerability
It was discovered that libvpx did not properly handle certain malformed media files. If an application using libvpx opened a specially crafted file, a remote attacker could cause a denial of service, or possibly execute arbitrary code. Ubuntu 22.04 LTS, Ubuntu 20.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 16.04 LTS were previously addressed in USN-6403-1, USN-6403-2, and USN-6403-3. This update addresses the issue in Ubuntu 14.04 LTS.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7172-1?
USN-7172-1 is considered a high severity vulnerability due to its potential for remote code execution and denial of service.
How do I fix USN-7172-1?
To fix USN-7172-1, upgrade to the corrected package version 1.3.0-2ubuntu0.1~esm3 or later.
What versions of Ubuntu are affected by USN-7172-1?
USN-7172-1 affects Ubuntu 22.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 18.04 LTS.
Can USN-7172-1 lead to remote code execution?
Yes, USN-7172-1 can potentially lead to remote code execution if exploited through a malicious media file.
Is it safe to open media files with libvpx after USN-7172-1?
It is not safe to open media files with libvpx prior to applying the security updates addressed in USN-7172-1.