Explore top 10 tips to secure your open-source projects now. Read More
×
An update for libvpx is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: libvpx security update Advisory ID: RHSA-2023:5539-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:5539 Issue date: 2023-10-09 CVE Names: CVE-2023-5217 CVE-2023-44488 ===================================================================== 1. Summary: An update for libvpx is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 9) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux CRB (v. 9) - aarch64, ppc64le, s390x, x86_64 3. Description: The libvpx packages provide the VP8 SDK, which allows the encoding and decoding of the VP8 video codec, commonly used with the WebM multimedia container file format. Security Fix(es): * libvpx: Heap buffer overflow in vp8 encoding in libvpx (CVE-2023-5217) * libvpx: crash related to VP9 encoding in libvpx (CVE-2023-44488) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, referto: https://access.redhat.com/articles/11258 After installing the update, all applications using libvpx must be restarted for the changes to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 2241191 - CVE-2023-5217 libvpx: Heap buffer overflow in vp8 encoding in libvpx 2241806 - CVE-2023-44488 libvpx: crash related to VP9 encoding in libvpx 6. Package List: Red Hat Enterprise Linux AppStream (v. 9): Source: libvpx-1.9.0-7.el9_2.src.rpm aarch64: libvpx-1.9.0-7.el9_2.aarch64.rpm libvpx-debuginfo-1.9.0-7.el9_2.aarch64.rpm libvpx-debugsource-1.9.0-7.el9_2.aarch64.rpm libvpx-utils-debuginfo-1.9.0-7.el9_2.aarch64.rpm ppc64le: libvpx-1.9.0-7.el9_2.ppc64le.rpm libvpx-debuginfo-1.9.0-7.el9_2.ppc64le.rpm libvpx-debugsource-1.9.0-7.el9_2.ppc64le.rpm libvpx-utils-debuginfo-1.9.0-7.el9_2.ppc64le.rpm s390x: libvpx-1.9.0-7.el9_2.s390x.rpm libvpx-debuginfo-1.9.0-7.el9_2.s390x.rpm libvpx-debugsource-1.9.0-7.el9_2.s390x.rpm libvpx-utils-debuginfo-1.9.0-7.el9_2.s390x.rpm x86_64: libvpx-1.9.0-7.el9_2.i686.rpm libvpx-1.9.0-7.el9_2.x86_64.rpm libvpx-debuginfo-1.9.0-7.el9_2.i686.rpm libvpx-debuginfo-1.9.0-7.el9_2.x86_64.rpm libvpx-debugsource-1.9.0-7.el9_2.i686.rpm libvpx-debugsource-1.9.0-7.el9_2.x86_64.rpm libvpx-utils-debuginfo-1.9.0-7.el9_2.i686.rpm libvpx-utils-debuginfo-1.9.0-7.el9_2.x86_64.rpm Red Hat Enterprise Linux CRB (v.9): aarch64: libvpx-debuginfo-1.9.0-7.el9_2.aarch64.rpm libvpx-debugsource-1.9.0-7.el9_2.aarch64.rpm libvpx-devel-1.9.0-7.el9_2.aarch64.rpm libvpx-utils-debuginfo-1.9.0-7.el9_2.aarch64.rpm ppc64le: libvpx-debuginfo-1.9.0-7.el9_2.ppc64le.rpm libvpx-debugsource-1.9.0-7.el9_2.ppc64le.rpm libvpx-devel-1.9.0-7.el9_2.ppc64le.rpm libvpx-utils-debuginfo-1.9.0-7.el9_2.ppc64le.rpm s390x: libvpx-debuginfo-1.9.0-7.el9_2.s390x.rpm libvpx-debugsource-1.9.0-7.el9_2.s390x.rpm libvpx-devel-1.9.0-7.el9_2.s390x.rpm libvpx-utils-debuginfo-1.9.0-7.el9_2.s390x.rpm x86_64: libvpx-debuginfo-1.9.0-7.el9_2.i686.rpm libvpx-debuginfo-1.9.0-7.el9_2.x86_64.rpm libvpx-debugsource-1.9.0-7.el9_2.i686.rpm libvpx-debugsource-1.9.0-7.el9_2.x86_64.rpm libvpx-devel-1.9.0-7.el9_2.i686.rpm libvpx-devel-1.9.0-7.el9_2.x86_64.rpm libvpx-utils-debuginfo-1.9.0-7.el9_2.i686.rpm libvpx-utils-debuginfo-1.9.0-7.el9_2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2023-5217 https://access.redhat.com/security/cve/CVE-2023-44488 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIcBAEBCAAGBQJlJBvQAAoJENzjgjWX9erEHmkP/j76TS36r/5pmVKxp+KznrJ2 B60LOzDV21Hhca6NRy/moHcSIfQEkty0fxWBQ8HqNrZ0mQRZNNFz1hOXZ097eH6B v9fRdFMeyqT5PFpPjU5y+gmyxt43ZCh7LEPBQvMGDCnkW4M8NUbE0y9uxjMiAe19 3zDDcLA+ssy7Z3K594ICHtuk5Rx8a5iIpRUbf63BBRTRlSPzsQ54FBi3zMSXIYDF lMcXbTHq8ysjjrUNDHag89Kg2Xt4XXoC9+W+E1PFqfnlZBzYttXb25yiJJfkvp9k s6AlYqjdQ0XHBpdiImuzknplOTFNIGfXePGM8cCqK5P752dmhg10RotbKNRCP8sj r/nlCUyXIV0RuFw6qDC0NFzxfXo8K/VUolHToa8BfxB+CzX+evRLDkCKJmEJv3wo /rt/W9lzALtXEwK+XqPs9pP/I9zRUXeaFocBKUaK8Mugiun8wwZfB5+sowa18+7V 8Y22YmtASXuAHhPPCRa1+UWpmzEwXRQMVnQcZSZfLadBJ141lJhMlwwoxbNNz+dj OBERh/JYwxBLWK80wmYjUa0751umz+P8UxrqEeA0OCpZ5Zt+GG9gMbVRIeYgP1kO LH4h27uhhRBDZ9rRnu3h7FWezeBvRRMwsCrElyEbQa/47aCmpOFIwqdiYwN26SCF YMobQwgofyBKFBn5GBId =/LcT -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for libvpx is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: libvpx security update Advisory ID: RHSA-2023:5540-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:5540 Issue date: 2023-10-09 CVE Names: CVE-2023-5217 CVE-2023-44488 ===================================================================== 1. Summary: An update for libvpx is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat CodeReady Linux Builder EUS (v.9.0) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux AppStream EUS (v.9.0) - aarch64, ppc64le, s390x, x86_64 3. Description: The libvpx packages provide the VP8 SDK, which allows the encoding and decoding of the VP8 video codec, commonly used with the WebM multimedia container file format. Security Fix(es): * libvpx: Heap buffer overflow in vp8 encoding in libvpx (CVE-2023-5217) * libvpx: crash related to VP9 encoding in libvpx (CVE-2023-44488) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Afterinstalling the update, all applications using libvpx must be restarted for the changes to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 2241191 - CVE-2023-5217 libvpx: Heap buffer overflow in vp8 encoding in libvpx 2241806 - CVE-2023-44488 libvpx: crash related to VP9 encoding in libvpx 6. Package List: Red Hat Enterprise Linux AppStream EUS (v.9.0): Source: libvpx-1.9.0-7.el9_0.src.rpm aarch64: libvpx-1.9.0-7.el9_0.aarch64.rpm libvpx-debuginfo-1.9.0-7.el9_0.aarch64.rpm libvpx-debugsource-1.9.0-7.el9_0.aarch64.rpm libvpx-utils-debuginfo-1.9.0-7.el9_0.aarch64.rpm ppc64le: libvpx-1.9.0-7.el9_0.ppc64le.rpm libvpx-debuginfo-1.9.0-7.el9_0.ppc64le.rpm libvpx-debugsource-1.9.0-7.el9_0.ppc64le.rpm libvpx-utils-debuginfo-1.9.0-7.el9_0.ppc64le.rpm s390x: libvpx-1.9.0-7.el9_0.s390x.rpm libvpx-debuginfo-1.9.0-7.el9_0.s390x.rpm libvpx-debugsource-1.9.0-7.el9_0.s390x.rpm libvpx-utils-debuginfo-1.9.0-7.el9_0.s390x.rpm x86_64: libvpx-1.9.0-7.el9_0.i686.rpm libvpx-1.9.0-7.el9_0.x86_64.rpm libvpx-debuginfo-1.9.0-7.el9_0.i686.rpm libvpx-debuginfo-1.9.0-7.el9_0.x86_64.rpm libvpx-debugsource-1.9.0-7.el9_0.i686.rpm libvpx-debugsource-1.9.0-7.el9_0.x86_64.rpm libvpx-utils-debuginfo-1.9.0-7.el9_0.i686.rpm libvpx-utils-debuginfo-1.9.0-7.el9_0.x86_64.rpm Red Hat CodeReady Linux Builder EUS(v.9.0): aarch64: libvpx-debuginfo-1.9.0-7.el9_0.aarch64.rpm libvpx-debugsource-1.9.0-7.el9_0.aarch64.rpm libvpx-devel-1.9.0-7.el9_0.aarch64.rpm libvpx-utils-debuginfo-1.9.0-7.el9_0.aarch64.rpm ppc64le: libvpx-debuginfo-1.9.0-7.el9_0.ppc64le.rpm libvpx-debugsource-1.9.0-7.el9_0.ppc64le.rpm libvpx-devel-1.9.0-7.el9_0.ppc64le.rpm libvpx-utils-debuginfo-1.9.0-7.el9_0.ppc64le.rpm s390x: libvpx-debuginfo-1.9.0-7.el9_0.s390x.rpm libvpx-debugsource-1.9.0-7.el9_0.s390x.rpm libvpx-devel-1.9.0-7.el9_0.s390x.rpm libvpx-utils-debuginfo-1.9.0-7.el9_0.s390x.rpm x86_64: libvpx-debuginfo-1.9.0-7.el9_0.i686.rpm libvpx-debuginfo-1.9.0-7.el9_0.x86_64.rpm libvpx-debugsource-1.9.0-7.el9_0.i686.rpm libvpx-debugsource-1.9.0-7.el9_0.x86_64.rpm libvpx-devel-1.9.0-7.el9_0.i686.rpm libvpx-devel-1.9.0-7.el9_0.x86_64.rpm libvpx-utils-debuginfo-1.9.0-7.el9_0.i686.rpm libvpx-utils-debuginfo-1.9.0-7.el9_0.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2023-5217 https://access.redhat.com/security/cve/CVE-2023-44488 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIcBAEBCAAGBQJlJBvHAAoJENzjgjWX9erEt90P/inRqz/DbnoWVjSgNcsuvarw GqTJtKEmHTNmn0Nqk3oAXDg1d8EMr+H8Iql6KHrmBUV2DwbrTniaaARn0/ZNes70 DSc65/kfbUbYxdvdHRp1lVqZSrTVA7FDr098h30pUF3TPOZfQP/ePYg2DjUn+jI4 s/x7DsJL7SnlI3xsZo3OKxoEIrp9M9l+U3LQJ3A4kN67bDnNOXFcA/uYQt58bSfE kX5CK2P8mSalbVC96w6y8sDsUr9ZcZGgtF8bzh6dh5vmAPP/e+v6lOECSTYmCCYb 126xDFEzJLZNMTkUvBaLkcE+M3isBwuNtJTumkDXMpH9CDkQ6QvoQH+JqHLkROOu gDX/55mR3i9UiSpK0OS22HuVU5I4PRAmlAdC2wm1kU3gm2qRBASz9d0fTUDXhVsg nJ5IgLfUAPOjY1N/IAantmWvmmSt191b3kHG+0+AEYMkwGWCIhXGbTg7PIuTvK9n Skxo2WwJ3B5+LiBayAaZ6z3dhdrxiPO+6jVez62Ujqse3BfwFjDrA0WNC3Hge3/H uGAJxdrDYR8Y4N3IL2qm+4pT1o+uGs03HueJdnFQBw4r/5asrCCx06qc70AlKO9d kD4Kwurr2BbAa4HzaKOijILfpLH+p2VXg2li8OT7yYsGc0Ienux5n7W0wHmRiqK/ 10Rfd+SBXPrj6eKf9sDx =fZBW -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Security fix for CVE-2023-5217. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-10ff82e497 2023-10-02 00:15:10.165441 -------------------------------------------------------------------------------- Name : libvpx Product : Fedora 39 Version : 1.13.0 Release : 5.fc39 URL : https://www.webmproject.org/code/ Summary : VP8/VP9 Video Codec SDK Description : libvpx provides the VP8/VP9 SDK, which allows you to integrate your applications with the VP8 and VP9 video codecs, high quality, royalty free, open source codecs deployed on millions of computers and devices worldwide. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2023-5217 -------------------------------------------------------------------------------- ChangeLog: * Fri Sep 29 2023 Neal Gompa - 1.13.0-5 - Minor spec cleanups * Thu Sep 28 2023 Boudhayan Bhattacharya - 1.13.0-4 - Patch for CVE-2023-5217 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2241260 - CVE-2023-5217 libvpx: Heap buffer overflow in vp8 encoding in libvpx [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2241260 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-10ff82e497' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
libvpx-1.3.0-7.fc21 - set --size-limit=16384x16384 to fix CVE-2015-1258 libvpx-1.3.0-7.fc22 - set --size-limit=16384x16384 to fix CVE-2015-1258 libvpx-1.4.0-5.fc23 - set --size-limit=16384x16384 to avoid CVE-2015-1258. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-15935 2015-10-05 18:13:04.391045 -------------------------------------------------------------------------------- Name : libvpx Product : Fedora 21 Version : 1.3.0 Release : 7.fc21 URL : Summary : VP8 Video Codec SDK Description : libvpx provides the VP8 SDK, which allows you to integrate your applications with the VP8 video codec, a high quality, royalty free, open source codec deployed on millions of computers and devices worldwide. -------------------------------------------------------------------------------- Update Information: libvpx-1.3.0-7.fc21 - set --size-limit=16384x16384 to fix CVE-2015-1258 libvpx-1.3.0-7.fc22 - set --size-limit=16384x16384 to fix CVE-2015-1258 libvpx-1.4.0-5.fc23 - set --size-limit=16384x16384 to avoid CVE-2015-1258 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1223266 - CVE-2015-1258 chromium-browser: Negative-size parameter in Libvpx. https://bugzilla.redhat.com/show_bug.cgi?id=1223266 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update libvpx' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailinglist
Get the latest Linux and open source security news straight to your inbox.