[ALSA-2023:5537] Important: libvpx security update
Type:
security
Severity:
important
Release date:
2023-10-10
Description:
The libvpx packages provide the VP8 SDK, which allows the encoding and decoding of the VP8 video codec, commonly used with the WebM multimedia container file format. Security Fix(es): * libvpx: Heap buffer overflow in vp8 encoding in libvpx (CVE-2023-5217) * libvpx: crash related to VP9 encoding in libvpx (CVE-2023-44488) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 libvpx-devel-1.7.0-10.el8_8.alma.1.aarch64.rpm 57255797b0ab07cba7ac589745970c749007aa94a73c9eae5def7ff7e496de5a
aarch64 libvpx-1.7.0-10.el8_8.alma.1.aarch64.rpm f30d5a5cd25fdb84606cb40a3e7ca141086237020e1e5a314d30e6b445de5551
i686 libvpx-1.7.0-10.el8_8.alma.1.i686.rpm 2f053ddefad49e7625095f7b0be2239f0f60914566eeca42007d3338ff6d6042
i686 libvpx-devel-1.7.0-10.el8_8.alma.1.i686.rpm d27b50db74f0264fcd0b584b810a757402bbf56fcec3aec88e8fb16aae14a0a6
ppc64le libvpx-devel-1.7.0-10.el8_8.alma.1.ppc64le.rpm 8488ea28f20442c81b05e6679c958dd4cf25d80721e10e916884a23dd0d82f65
ppc64le libvpx-1.7.0-10.el8_8.alma.1.ppc64le.rpm b25078edd683725bc6e9d095be3b408e97bcc54217f5d497689035598363012c
s390x libvpx-1.7.0-10.el8_8.alma.1.s390x.rpm 09ecc1b7a6e9a79272b6a712956b0201dd9c3fc98eb03240144bf97b20207393
s390x libvpx-devel-1.7.0-10.el8_8.alma.1.s390x.rpm 8f760e7d575c1ab48edad35b0f971a542f2fc94d984f00103acd2ab26cf4ac05
x86_64 libvpx-1.7.0-10.el8_8.alma.1.x86_64.rpm 895a48b844d6d5cfd97d3fc1894bdc411f31c6001523b123c55b99f58e4a20ce
x86_64 libvpx-devel-1.7.0-10.el8_8.alma.1.x86_64.rpm e0de12c448cc711c1ccb10ec4dd9119f4e8baa08ba5c257c4b315da56814976f
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.