[ALSA-2024:5941] Moderate: libvpx security update
Type:
security
Severity:
moderate
Release date:
2024-08-29
Description:
The libvpx packages provide the VP8 SDK, which allows the encoding and decoding of the VP8 video codec, commonly used with the WebM multimedia container file format. Security Fix(es): * libvpx: Heap buffer overflow related to VP9 encoding (CVE-2023-6349) * libvpx: Integer overflow in vpx_img_alloc() (CVE-2024-5197) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 libvpx-1.7.0-11.el8_10.aarch64.rpm 228cc4f2ee166a20ffbff5e6e6d8187d974efbd86360fe513b57b07475fa0f6d
aarch64 libvpx-devel-1.7.0-11.el8_10.aarch64.rpm c92c3caceacac0ad3eba128aeafe5a3c32ff7e417cbcdfa65156e6bf59e69b47
i686 libvpx-devel-1.7.0-11.el8_10.i686.rpm 757a258fc6ab949e4ecfa4510c1f015b6396140f06bec46cd6c698e8e84006a3
i686 libvpx-1.7.0-11.el8_10.i686.rpm 7636fc121499a68fc070c3a85dc2b3d8150326682283ca909ba5b0927a0fa237
ppc64le libvpx-1.7.0-11.el8_10.ppc64le.rpm 8438a86d2ba5711fb3593a725b473b2665ed4a109f45b3eabf4b89757534569c
ppc64le libvpx-devel-1.7.0-11.el8_10.ppc64le.rpm d73e931bf59711b0c24071465c324c4c9e23191c764a269ef2b571f855921492
s390x libvpx-1.7.0-11.el8_10.s390x.rpm 632c071259c5ae83dce785c73c329656700b732c6f769c09bdf66b9614a1f4fb
s390x libvpx-devel-1.7.0-11.el8_10.s390x.rpm c9996989cbb6b379e496e22919778ccdf73528b6dfad54f54d8b74e59cbe2bb1
x86_64 libvpx-1.7.0-11.el8_10.x86_64.rpm 147804e60a5deabcc095cef794943e2b4eb8f952a78cb1cbd2d0c94165fa1d81
x86_64 libvpx-devel-1.7.0-11.el8_10.x86_64.rpm 517ca42b8ccf7c84f43750c0bbd98254d09628a86e2f27c2c4d18d66a3522438
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.