[ALSA-2023:5539] Important: libvpx security update
Type:
security
Severity:
important
Release date:
2023-10-09
Description:
The libvpx packages provide the VP8 SDK, which allows the encoding and decoding of the VP8 video codec, commonly used with the WebM multimedia container file format. Security Fix(es): * libvpx: Heap buffer overflow in vp8 encoding in libvpx (CVE-2023-5217) * libvpx: crash related to VP9 encoding in libvpx (CVE-2023-44488) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 libvpx-devel-1.9.0-7.el9_2.alma.1.aarch64.rpm 2c273738b6876ddf72f259ec21e4d69f34ff5601c35cd8c5e4c83e18c07e4d42
aarch64 libvpx-1.9.0-7.el9_2.alma.1.aarch64.rpm 8f14dad1b7785a3ae3ffcc030ae8f8e80170b4fbae15252f8a1bd752c2c39d5e
i686 libvpx-1.9.0-7.el9_2.alma.1.i686.rpm 43ac6a8e1233e52b34a5e59d05c048c64cdf0e662b8b5c8eba60204063ff614c
i686 libvpx-devel-1.9.0-7.el9_2.alma.1.i686.rpm b18fadc95b5f26dbeda74594cf5b89ba7435467914a3d182ee43132134488970
ppc64le libvpx-1.9.0-7.el9_2.alma.1.ppc64le.rpm 88cd967f4d67d785ee07d195a27a30dda42c56ed69289da781287ddae8189c76
ppc64le libvpx-devel-1.9.0-7.el9_2.alma.1.ppc64le.rpm 9cad50ef00815afbbc749d91de15e9fe40a3038ac342ae07975d520a18525d5c
s390x libvpx-1.9.0-7.el9_2.alma.1.s390x.rpm 2e673b6423cbb24c2824ec5efeacee4b8cbb8d075dce7d6e8d9061ab154263bd
s390x libvpx-devel-1.9.0-7.el9_2.alma.1.s390x.rpm 6e7ecf0eb9613ff4b282387ae15b790e678976cd4784a2187ec3e377acffbeb2
x86_64 libvpx-1.9.0-7.el9_2.alma.1.x86_64.rpm 76649070726f2d374e967764d907a360c93abfcaa804326bbdec855105abbe4c
x86_64 libvpx-devel-1.9.0-7.el9_2.alma.1.x86_64.rpm fcd57fa049feec8b22f53adcdd038ddc6499f4b4a9dd902f28db232f95fee1a5
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.