-----BEGIN PGP SIGNATURE-----
wsF5BAABCAAjFiEEyMDHOTG0YH5UsajI8pSCVQZYHygFAmeiIu0FAwAAAAAACgkQ8pSCVQZYHyjf
PQ//fg/aniZsGSsfx9cppPtjqU3EfoE49qWTrTMScUz9a0pkVyWQkbWipfqxwT7ExpaXAjM+U+uW
BlRSb4ymNKH1PDSphjDXkTdZ6U12emzAxcblu2XE4+sOijuBEXVKrnSLsZ43Oy9aDMCprflmQqre
dd5VSJnJ8T+40IToZ/z0JjWdNZN/7QkxplBnjPBymPYC0RZQn6KrCT+1UfDqbX39xi4UTENlwmP6
YQJY7XbxfzcNSuYQJs2FgJDTbkFZgF2qIMGuXg2LzCbvJboqbaY4G7w/8JRaKjN7z8hieUE6hDwl
rYf+6dL7VxFEoe2kVDI5gQ9tCxfFBOJnpo6kbQf0l3OTpcrDC0JrLMcWLvnUO3bWudXc1770sqcs
ZNYqzDuVGr+XBDAePwyYbpN9Rqp2D0XDvpdp+mT7cKXt++yKktx9yoC/bm+4Bz8f67bJoPGQA6/w
ijvSBoz+H2FNurg7KNUoUBWjf4hpV/KwKNGtIjk/OtkorLT1kEjWNuznCo//oyCg/SbY+8E40/f7
CRoZEmktNx41bbRC686LLOHudkZa3SRhArAMLVHuafoIy3kmikbmOHFcAqQzSXwZ19aDiEX/GoUa
0FIp/4EbsK/RBkvin7t/nscNA0UGqnmzE7l42ZkWu2jXw2q3nbwgv03geDixjxW02ar0UEqHuJTL
My0=
=CYav
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7249-1
February 03, 2025
libvpx vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS
Summary:
libvpx could be made to crash or run programs as your login if it
opened a specially crafted image file.
Software Description:
- libvpx: VP8 and VP9 video codec
Details:
Xiantong Hou discovered that libvpx would overflow when attempting to
allocate memory for very large images. If an application using libvpx
opened a specially crafted file, a remote attacker could possibly use
this issue to cause the application to crash, resulting in a denial
of service, or the execution of arbitrary code.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 18.04 LTS
libvpx5 1.7.0-3ubuntu0.18.04.1+esm2
Available with Ubuntu Pro
vpx-tools 1.7.0-3ubuntu0.18.04.1+esm2
Available with Ubuntu Pro
Ubuntu 16.04 LTS
libvpx3 1.5.0-2ubuntu1.1+esm3
Available with Ubuntu Pro
vpx-tools 1.5.0-2ubuntu1.1+esm3
Available with Ubuntu Pro
Ubuntu 14.04 LTS
libvpx1 1.3.0-2ubuntu0.1+esm3
Available with Ubuntu Pro
vpx-tools 1.3.0-2ubuntu0.1+esm3
Available with Ubuntu Pro
In general, a standard system update will make all the
necessary changes.
References:
https://ubuntu.com/security/notices/USN-7249-1
CVE-2024-5197
No comments:
Post a Comment