AOM could be made to crash or run programs if it opened a specially crafted file.. ========================================================================== Ubuntu Security Notice USN-7397-1 March 31, 2025 aom vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: AOM could be made to crash or run programs if it opened a specially crafted file. Software Description: - aom: AV1 Video Codec Library Details: Xiantong Hou discovered that AOM did not properly handle certain malformed media files. If an application using AOM opened a specially crafted file, a remote attacker could cause a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS aom-tools 3.3.0-1ubuntu0.1 libaom-dev 3.3.0-1ubuntu0.1 libaom3 3.3.0-1ubuntu0.1 Ubuntu 20.04 LTS aom-tools 1.0.0.errata1-3+deb11u1ubuntu0.1 libaom-dev 1.0.0.errata1-3+deb11u1ubuntu0.1 libaom0 1.0.0.errata1-3+deb11u1ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7397-1 CVE-2024-5171 Package Information: https://launchpad.net/ubuntu/+source/aom/3.3.0-1ubuntu0.1 https://launchpad.net/ubuntu/+source/aom/1.0.0.errata1-3+deb11u1ubuntu0.1 . AOM vulnerability advisory for Ubuntu: critical update to prevent crashes or code execution from crafted files.. crash, programs, opened, specially, crafted, ==================. . Severity: Important. LinuxSecurity.com Team
Integer overflows have been fixed in aom, an AV1 Codec Library. For Debian 11 bullseye, this problem has been fixed in version 1.0.0.errata1-3+deb11u2. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3881-1
Integer overflow in libaom internal function img_alloc_helper can lead to heap buffer overflow. This function can be reached via 3 callers: * Calling aom_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned aom_image_t struct may . MGASA-2024-0220 - Updated aom packages fix security vulnerability Publication date: 14 Jun 2024 URL: https://advisories.mageia.org/MGASA-2024-0220.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-5171 Integer overflow in libaom internal function img_alloc_helper can lead to heap buffer overflow. This function can be reached via 3 callers: * Calling aom_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned aom_image_t struct may be invalid. * Calling aom_img_wrap() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned aom_image_t struct may be invalid. * Calling aom_img_alloc_with_border() with a large value of the d_w, d_h, align, size_align, or border parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned aom_image_t struct may be invalid. (CVE-2024-5171) References: - https://bugs.mageia.org/show_bug.cgi?id=33280 - https://ubuntu.com/security/notices/USN-6815-1 - https://www.cve.org/CVERecord?id=CVE-2024-5171 SRPMS: - 9/core/aom-3.6.0-1.1.mga9 . The latest aom packages have addressed critical security vulnerabilities arising from integer overflow, which may lead to buffer overflow threats in Mageia.. integer Overflow, buffer Overflow, libaom security, Mageia Advisory. . LinuxSecurity.com Team
AOM could be made to crash or run programs if it opened a specially crafted file.. ========================================================================== Ubuntu Security Notice USN-6815-1 June 06, 2024 aom vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS Summary: AOM could be made to crash or run programs if it opened a specially crafted file. Software Description: - aom: AV1 Video Codec Library Details: Xiantong Hou discovered that AOM did not properly handle certain malformed media files. If an application using AOM opened a specially crafted file, a remote attacker could cause a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS libaom3 3.8.2-2ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6815-1 CVE-2024-5171 Package Information: https://launchpad.net/ubuntu/+source/aom/3.8.2-2ubuntu0.1 . A critical flaw enables remote crashes or arbitrary code execution in Ubuntu 24.04 LTS. Ensure your systems are patched promptly.. AOM Security Advisory, Ubuntu 24.04, Crash Risk, Denial of Service, Code Execution. . Severity: Critical. LinuxSecurity.com Team
Multiple security vulnerabilities have been discovered in aom, the AV1 Video Codec Library. Buffer overflows, use-after-free and NULL pointer dereferences may cause a denial of service or other unspecified impact if a malformed multimedia file is processed. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3556-1
Multiple security vulnerabilities have been discovered in aom, the AV1 Video Codec Library. Buffer overflows, use-after-free and NULL pointer dereferences may cause a denial of service or other unspecified impact if a malformed multimedia file is processed. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5490-1
Get the latest Linux and open source security news straight to your inbox.