Alerts This Week
Warning Icon 1 640
Alerts This Week
Warning Icon 1 640

Ubuntu 14.04 ESM: USN-4199-2 Critical: Libvpx Denial Of Service

ubuntu
Calendar Grey July 15, 2020
Dist Ubuntu Esm H88
Ubuntu Security Summary USN-4200-1 highlights vulnerabilities in libwebp that can lead to remote exploitation and Denial-of-Service scenarios.
Several security issues were fixed in libvpx.

Summary

Several security issues were fixed in libvpx.

Software Description:

- libvpx: VP8 and VP9 video codec

Details:

USN-4199-1 fixed several vulnerabilities in libvpx. This update provides

the corresponding update for Ubuntu 14.04 ESM.

Original advisory details:

It was discovered that libvpx did not properly handle certain malformed

WebM media files. If an application using libvpx opened a specially crafted

WebM file, a remote attacker could cause a denial of service, or possibly

execute arbitrary code.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 ESM:
  libvpx1                         1.3.0-2ubuntu0.1~esm1

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-4199-2

https://ubuntu.com/security/notices/USN-4199-1

CVE-2017-13194, CVE-2019-9232, CVE-2019-9433

Severity
critical
Lowest
Low
Medium
High
Critical

July 15, 2020

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here