CVE-2024-5197
published 2024-06-03CVE-2024-5197: There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the d_w, d_h, or align parameter may…
PriorityP347critical9.1CVSS 3.1
AVNACLPRNUINSUCNIHAH
EPSS
0.81%
52.9th percentile
There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. Calling vpx_img_wrap() with a large value of the d_w, d_h, or stride_align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. We recommend upgrading to version 1.14.1 or beyond
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | libvpx | < 1.14.1 | 1.14.1 |
| debian | debian_linux | — | — |
| debian | libvpx | < libvpx 1.12.0-1+deb12u3 (bookworm) | libvpx 1.12.0-1+deb12u3 (bookworm) |
| webmproject | libvpx | < 1.14.1 | 1.14.1 |
| webmproject | libvpx | >= 0 < 1.9.0-1+deb11u3 | 1.9.0-1+deb11u3 |
| webmproject | libvpx | >= 0 < 1.12.0-1+deb12u3 | 1.12.0-1+deb12u3 |
| webmproject | libvpx | >= 0 < 1.14.1-1 | 1.14.1-1 |
| webmproject | libvpx | >= 0 < 1.14.1-1 | 1.14.1-1 |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
nvdv4.05.9MEDIUMCVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:L/VI:H/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libvpx vulnerability
vendor_ubuntu·2025-02-03
CVE-2024-5197 libvpx vulnerability
Title: libvpx vulnerability
Summary: libvpx could be made to crash or run programs as your login if it
opened a specially crafted image file.
Xiantong Hou discovered that libvpx would overflow when attempting to
allocate memory for very large images. If an application using libvpx
opened a specially crafted file, a remote attacker could possibly use
this issue to cause the application to crash, resulting in a denial
of service, or the execution of arbitrary code.
Instructions: In general, a standard system update will make all the
necessary changes.
Ubuntu
libvpx vulnerability
vendor_ubuntu·2024-06-06
CVE-2024-5197 libvpx vulnerability
Title: libvpx vulnerability
Summary: libvpx could be made to crash or run programs if it opened a specially
crafted file.
Xiantong Hou discovered that libvpx did not properly handle certain
malformed media files. If an application using libvpx opened a specially
crafted file, a remote attacker could cause a denial of service, or
possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libvpx: Integer overflow in vpx_img_alloc()
vendor_redhat·2024-06-04·CVSS 5.9
CVE-2024-5197 [MEDIUM] CWE-190 libvpx: Integer overflow in vpx_img_alloc()
libvpx: Integer overflow in vpx_img_alloc()
There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. Calling vpx_img_wrap() with a large value of the d_w, d_h, or stride_align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. We recommend upgrading to version 1.14.1 or beyond
A flaw was found in libvpx. When creating images, libvpx trusts the width, height, and alignment of the user input. However, it does not properly validate the provided values
Debian
CVE-2024-5197: libvpx - There exists interger overflows in libvpx in versions prior to 1.14.1. Calling v...
vendor_debian·2024·CVSS 5.9
CVE-2024-5197 [MEDIUM] CVE-2024-5197: libvpx - There exists interger overflows in libvpx in versions prior to 1.14.1. Calling v...
There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. Calling vpx_img_wrap() with a large value of the d_w, d_h, or stride_align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. We recommend upgrading to version 1.14.1 or beyond
Scope: local
bookworm: resolved (fixed in 1.12.0-1+deb12u3)
bullseye: resolved (fixed in 1.9.0-1+deb11u3)
forky: resolved (fixed in 1.14.1-1)
sid: resolved (fixed in 1.14.1-1)
trixie: resolved (fixed in 1.14.1-1)
GHSA
GHSA-4h58-f788-v8pw: There exists interger overflows in libvpx in versions prior to 1
ghsa_unreviewed·2024-06-03
CVE-2024-5197 [MEDIUM] CWE-190 GHSA-4h58-f788-v8pw: There exists interger overflows in libvpx in versions prior to 1
There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. Calling vpx_img_wrap() with a large value of the d_w, d_h, or stride_align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. We recommend upgrading to version 1.14.1 or beyond
OSV
CVE-2024-5197: There exists interger overflows in libvpx in versions prior to 1
osv·2024-06-03·CVSS 5.9
CVE-2024-5197 [MEDIUM] CVE-2024-5197: There exists interger overflows in libvpx in versions prior to 1
There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. Calling vpx_img_wrap() with a large value of the d_w, d_h, or stride_align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. We recommend upgrading to version 1.14.1 or beyond
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-06-03
Published