CVE-2023-44488
published 2023-09-30CVE-2023-44488: VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding.
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.94%
77.8th percentile
VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libvpx | < libvpx 1.12.0-1+deb12u2 (bookworm) | libvpx 1.12.0-1+deb12u2 (bookworm) |
| fedoraproject | fedora | — | — |
| msrc | azl3_mozjs_102.15.1-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_libvpx_1.13.1-1_on_cbl_mariner_2.0 | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| webmproject | libvpx | < 1.13.1 | 1.13.1 |
| webmproject | libvpx | >= 0 < 1.9.0-1+deb11u2 | 1.9.0-1+deb11u2 |
| webmproject | libvpx | >= 0 < 1.12.0-1+deb12u2 | 1.12.0-1+deb12u2 |
| webmproject | libvpx | >= 0 < 1.12.0-1.2 | 1.12.0-1.2 |
| webmproject | libvpx | >= 0 < 1.12.0-1.2 | 1.12.0-1.2 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libvpx vulnerabilities
vendor_ubuntu·2023-11-01
CVE-2023-44488 libvpx vulnerabilities
Title: libvpx vulnerabilities
Summary: Several security issues were fixed in libvpx.
USN-6403-1 fixed several vulnerabilities in libvpx. This update provides
the corresponding update for Ubuntu 16.04 LTS.
Original advisory details:
It was discovered that libvpx did not properly handle certain malformed
media files. If an application using libvpx opened a specially crafted
file, a remote attacker could cause a denial of service, or possibly
execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
libvpx vulnerabilities
vendor_ubuntu·2023-10-23
CVE-2023-5217 libvpx vulnerabilities
Title: libvpx vulnerabilities
Summary: Several security issues were fixed in libvpx.
USN-6403-1 fixed several vulnerabilities in libvpx. This update provides
the corresponding update for Ubuntu 18.04 LTS.
Original advisory details:
It was discovered that libvpx did not properly handle certain malformed
media files. If an application using libvpx opened a specially crafted
file, a remote attacker could cause a denial of service, or possibly
execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
libvpx vulnerabilities
vendor_ubuntu·2023-10-02
CVE-2023-44488 libvpx vulnerabilities
Title: libvpx vulnerabilities
Summary: Several security issues were fixed in libvpx.
It was discovered that libvpx did not properly handle certain malformed
media files. If an application using libvpx opened a specially crafted
file, a remote attacker could cause a denial of service, or possibly
execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libvpx: crash related to VP9 encoding in libvpx
vendor_redhat·2023-09-30·CVSS 7.5
CVE-2023-44488 [HIGH] CWE-755 libvpx: crash related to VP9 encoding in libvpx
libvpx: crash related to VP9 encoding in libvpx
VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding.
A heap-based buffer overflow flaw was found in libvpx, a library used to process VP9 video codecs data. This issue occurs when processing certain specially formatted video data via a crafted HTML page, allowing an attacker to crash or remotely execute arbitrary code in an application, such as a web browser that is compiled with this library.
Statement: This security issue has been classified as having an Important security impact. Desktop users are at a high risk of exploitation of this flaw with very minimal interaction. It may compromise the confidentiality, integrity, or availability of resources.
Customers using this application, which does server-si
Microsoft
VP9 in libvpx before 1.13.1 mishandles widths leading to a crash related to encoding.
vendor_msrc·2023-09-12·CVSS 7.5
CVE-2023-44488 [HIGH] CWE-755 VP9 in libvpx before 1.13.1 mishandles widths leading to a crash related to encoding.
VP9 in libvpx before 1.13.1 mishandles widths leading to a crash related to encoding.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
Remediation: CBL-Mariner Rele
Debian
CVE-2023-44488: libvpx - VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to enc...
vendor_debian·2023·CVSS 7.5
CVE-2023-44488 [HIGH] CVE-2023-44488: libvpx - VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to enc...
VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding.
Scope: local
bookworm: resolved (fixed in 1.12.0-1+deb12u2)
bullseye: resolved (fixed in 1.9.0-1+deb11u2)
forky: resolved (fixed in 1.12.0-1.2)
sid: resolved (fixed in 1.12.0-1.2)
trixie: resolved (fixed in 1.12.0-1.2)
OSV
CVE-2023-44488: VP9 in libvpx before 1
osv·2023-09-30·CVSS 7.5
CVE-2023-44488 [HIGH] CVE-2023-44488: VP9 in libvpx before 1
VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding.
GHSA
GHSA-wc24-pw3j-j6vw: VP9 in libvpx before 1
ghsa_unreviewed·2023-09-30
CVE-2023-44488 [HIGH] CWE-755 GHSA-wc24-pw3j-j6vw: VP9 in libvpx before 1
VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2023/09/30/4https://bugzilla.redhat.com/show_bug.cgi?id=2241806https://github.com/webmproject/libvpx/commit/263682c9a29395055f3b3afe2d97be1828a6223fhttps://github.com/webmproject/libvpx/commit/df9fd9d5b7325060b2b921558a1eb20ca7880937https://github.com/webmproject/libvpx/compare/v1.13.0...v1.13.1https://github.com/webmproject/libvpx/releases/tag/v1.13.1https://lists.debian.org/debian-lts-announce/2023/10/msg00001.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TE7F54W5O5RS4ZMAAC7YK3CZWQXIDSKB/https://security.gentoo.org/glsa/202310-04https://www.debian.org/security/2023/dsa-5518http://www.openwall.com/lists/oss-security/2023/09/30/4https://bugzilla.redhat.com/show_bug.cgi?id=2241806https://github.com/webmproject/libvpx/commit/263682c9a29395055f3b3afe2d97be1828a6223fhttps://github.com/webmproject/libvpx/commit/df9fd9d5b7325060b2b921558a1eb20ca7880937https://github.com/webmproject/libvpx/compare/v1.13.0...v1.13.1https://github.com/webmproject/libvpx/releases/tag/v1.13.1https://lists.debian.org/debian-lts-announce/2023/10/msg00001.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TE7F54W5O5RS4ZMAAC7YK3CZWQXIDSKB/https://security.gentoo.org/glsa/202310-04https://www.debian.org/security/2023/dsa-5518
2023-09-30
Published