USN-7249-1: libvpx vulnerability
Xiantong Hou discovered that libvpx would overflow when attempting to allocate memory for very large images. If an application using libvpx opened a specially crafted file, a remote attacker could possibly use this issue to cause the application to crash, resulting in a denial of service, or the execution of arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7249-1?
USN-7249-1 is classified as a vulnerability that could lead to a denial of service due to a memory overflow issue.
How do I fix USN-7249-1?
To fix USN-7249-1, update the libvpx and vpx-tools packages to the specified remedied versions for your Ubuntu release.
Which versions of libvpx are affected by USN-7249-1?
USN-7249-1 affects versions of libvpx up to 1.7.0-3ubuntu0.18.04.1+esm2 for Ubuntu 18.04 and earlier versions of libvpx for Ubuntu 16.04 and 14.04.
What causes the vulnerability in USN-7249-1?
The vulnerability in USN-7249-1 is caused by an overflow when allocating memory for very large images in libvpx.
Who discovered the vulnerability in USN-7249-1?
The vulnerability in USN-7249-1 was discovered by Xiantong Hou.