PT-2019-5091 · Google+2 · Libvpx+3

Moritz Mühlenhoff

·

Published

2019-09-27

·

Updated

2024-06-15

·

CVE-2019-9325

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions libvpx versions prior to the fixed version Android versions Android-10
Description The issue is related to a missing bounds check in libvpx, which could lead to a possible out of bounds read. This may result in remote information disclosure without requiring additional execution privileges. User interaction is necessary for exploitation.
Recommendations For libvpx, update to a version that includes the fix for the out of bounds read issue. For Android versions Android-10, apply the security patch that addresses the libvpx vulnerability. As a temporary workaround, consider restricting access to multimedia content that utilizes the libvpx library until a patch is available.

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-01757
CVE-2019-9325
DSA-4578-1
OPENSUSE-SU-2020:0105-1
OPENSUSE-SU-2020_0105-1
OPENSUSE-SU-2024:11010-1
SUSE-SU-2020:0143-1
USN-4199-1

Affected Products

Android
Suse
Ubuntu
Libvpx