A heap overflow vulnerability exists in libvpx - Encoding a frame that has larger dimensions than the originally configured size with VP9 may result in a heap overflow in libvpx. We recommend upgrading to version 1.13.1 or above
{ "binaries": [ { "binary_name": "libvpx1", "binary_version": "1.3.0-2ubuntu0.1+esm3" }, { "binary_name": "vpx-tools", "binary_version": "1.3.0-2ubuntu0.1+esm3" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-6349.json"
{ "binaries": [ { "binary_name": "libvpx3", "binary_version": "1.5.0-2ubuntu1.1+esm2" }, { "binary_name": "vpx-tools", "binary_version": "1.5.0-2ubuntu1.1+esm2" } ], "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro" }
{ "binaries": [ { "binary_name": "libvpx5", "binary_version": "1.7.0-3ubuntu0.18.04.1+esm1" }, { "binary_name": "vpx-tools", "binary_version": "1.7.0-3ubuntu0.18.04.1+esm1" } ], "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro" }
{ "binaries": [ { "binary_name": "libvpx6", "binary_version": "1.8.2-1ubuntu0.2" }, { "binary_name": "vpx-tools", "binary_version": "1.8.2-1ubuntu0.2" } ], "availability": "No subscription required" }
{ "binaries": [ { "binary_name": "libvpx7", "binary_version": "1.11.0-2ubuntu2.2" }, { "binary_name": "vpx-tools", "binary_version": "1.11.0-2ubuntu2.2" } ], "availability": "No subscription required" }