There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. Calling vpx_img_wrap() with a large value of the d_w, d_h, or stride_align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. We recommend upgrading to version 1.14.1 or beyond
History

Wed, 28 Aug 2024 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat enterprise Linux
CPEs cpe:/a:redhat:enterprise_linux:8
Vendors & Products Redhat
Redhat enterprise Linux

cve-icon MITRE

Status: PUBLISHED

Assigner: Google

Published: 2024-06-03T13:30:26.925Z

Updated: 2024-08-01T21:03:11.058Z

Reserved: 2024-05-22T09:42:54.906Z

Link: CVE-2024-5197

cve-icon Vulnrichment

Updated: 2024-08-01T21:03:11.058Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-06-03T14:15:09.520

Modified: 2024-06-16T21:15:50.820

Link: CVE-2024-5197

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-06-04T00:00:00Z

Links: CVE-2024-5197 - Bugzilla