libvpx: Out of bounds read in vp8_decode_frame in decodeframe.c
Published Mar 10, 2020
7.5
HIGHCVSS 3.1
EPSS 1.94%
Description
In vp8_decode_frame of decodeframe.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure if error correction were turned on, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1Android ID: A-62458770
Affected products
- Vendor n/a Product Android Defaultunknown
Affected
- Android-8.0 Android-8.1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | Android | unknown | Affected
|
No data.
Red Hat Enterprise Linux 7
libvpx-0:1.3.0-8.el7
Fixed · RHSA-2020:3876
Red Hat Enterprise Linux 6
libvpx
Out of support scope
Red Hat Enterprise Linux 8
libvpx
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | libvpx-0:1.3.0-8.el7 | Fixed | RHSA-2020:3876 |
| Red Hat Enterprise Linux 6 | libvpx | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | libvpx | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The version shipped with Red Hat Enterprse Linux 8 already contains the commit which fix this issue, thus this version is not affected.
References (8)
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00048.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2020-0034 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1813000 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-1542 Advisory
- https://lists.debian.org/debian-lts-announce/2021/11/msg00024.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-0034
- https://source.android.com/security/bulletin/2020-03-01 x_refsource_MISCVendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-0034
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00048.html | vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2020-0034 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1813000 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-1542 | Advisory | |
| https://lists.debian.org/debian-lts-announce/2021/11/msg00024.html | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-0034 | ||
| https://source.android.com/security/bulletin/2020-03-01 | x_refsource_MISCVendor Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2020-0034 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data