- ------------------------------------------------------------------------- Debian LTS Advisory DLA-3598-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Emilio Pozuelo Monfort October 01, 2023 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : libvpx Version : 1.7.0-3+deb10u2 CVE ID : CVE-2023-5217 CVE-2023-44488 Two buffer overflow vulnerabilities were found in libvpx, a multimedia library for the VP8 and VP9 video codecs, which could result in the execution of arbitrary code if a specially crafted VP8 or VP9 media stream is processed. For Debian 10 buster, these problems have been fixed in version 1.7.0-3+deb10u2. We recommend that you upgrade your libvpx packages. For the detailed security status of libvpx please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libvpx Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS