Back

HIGH

libvpx: Out of bounds read in vp8_decode_frame in decodeframe.c

Published Mar 10, 2020

Description

In vp8_decode_frame of decodeframe.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure if error correction were turned on, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1Android ID: A-62458770

Affected products

Remediation

Red Hat statement

The version shipped with Red Hat Enterprse Linux 8 already contains the commit which fix this issue, thus this version is not affected.

References (8)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner google_android
Published Mar 10, 2020
Updated Aug 4, 2024
Reserved Oct 17, 2019

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Mar 2, 2020
Bugzilla 1813000

ENISA EUVD

Assigner google_android
Published Mar 10, 2020
Updated Aug 4, 2024

GitHub

No data