PT-2019-5087 · Google+6 · Libvpx+7

Published

2019-09-27

·

Updated

2024-06-15

·

CVE-2019-9232

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions libvpx (affected versions not specified) Android versions Android-10
Description The issue is related to a buffer memory out-of-bounds read in the libvpx multimedia library. This could allow a remote attacker to access confidential data. The exploitation does not require user interaction or additional execution privileges.
Recommendations For libvpx, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Android versions Android-10, update to a version that includes the fix for the issue, as identified by Android ID A-122675483.

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2020:4629
BDU:2020-01753
CESA-2020_3876
CESA-2020_4629
CVE-2019-9232
DLA-2012-1
DSA-4578-1
OPENSUSE-SU-2020:0105-1
OPENSUSE-SU-2020_0105-1
OPENSUSE-SU-2024:11010-1
RHSA-2020:3876
RHSA-2020:4629
RHSA-2020_3876
RHSA-2020_4629
RLSA-2020:4629
SUSE-SU-2020:0143-1
SUSE-SU-2020:0459-1
SUSE-SU-2020_0459-1
USN-4199-1
USN-4199-2

Affected Products

Almalinux
Android
Centos
Red Hat
Rocky Linux
Suse
Ubuntu
Libvpx