Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia: 2022-0040 Moderate: AOM Stack Buffer Overflow Advisory

mageia
Calendar Grey January 27, 2022
Dist Mageia Esm H88
MGASA-2022-0041 pertains to security flaws in AOM version 2.0.2, highlighting risks such as memory corruption vulnerabilities and improper resource management.
AOM v2.0.1 was discovered to contain a stack buffer overflow via the component src/aom_image.c

Summary

AOM v2.0.1 was discovered to contain a stack buffer overflow via the component src/aom_image.c. (CVE-2020-36129)
AOM v2.0.1 was discovered to contain a NULL pointer dereference via the component av1/av1_dx_iface.c. (CVE-2020-36130)
AOM v2.0.1 was discovered to contain a stack buffer overflow via the component stats/rate_hist.c. (CVE-2020-36131)
AOM v2.0.1 was discovered to contain a global buffer overflow via the component av1/encoder/partition_search.h. (CVE-2020-36133)
AOM v2.0.1 was discovered to contain a NULL pointer dereference via the component rate_hist.c. (CVE-2020-36135)

References

- https://bugs.mageia.org/show_bug.cgi?id=29808

- https://lists.suse.com/pipermail/sle-security-updates/2021-December/009940.html

-

- https://www.cve.org/CVERecord?id=CVE-2020-36129

- https://www.cve.org/CVERecord?id=CVE-2020-36130

- https://www.cve.org/CVERecord?id=CVE-2020-36131

- https://www.cve.org/CVERecord?id=CVE-2020-36133

- https://www.cve.org/CVERecord?id=CVE-2020-36135

Resolution

SRPMS

- 8/core/aom-2.0.1-3.5.mga8

Publication date: 27 Jan 2022
URL: https://advisories.mageia.org/MGASA-2022-0040.html
Type: security
CVE: CVE-2020-36129, CVE-2020-36130, CVE-2020-36131, CVE-2020-36133, CVE-2020-36135

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here