USN-7249-1: libvpx vulnerability
3 February 2025
libvpx could be made to crash or run programs as your login if it opened a specially crafted image file.
Releases
Packages
- libvpx - VP8 and VP9 video codec
Details
Xiantong Hou discovered that libvpx would overflow when attempting to
allocate memory for very large images. If an application using libvpx
opened a specially crafted file, a remote attacker could possibly use
this issue to cause the application to crash, resulting in a denial
of service, or the execution of arbitrary code.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 18.04
-
libvpx5
-
1.7.0-3ubuntu0.18.04.1+esm2
Available with Ubuntu Pro
-
vpx-tools
-
1.7.0-3ubuntu0.18.04.1+esm2
Available with Ubuntu Pro
Ubuntu 16.04
-
libvpx3
-
1.5.0-2ubuntu1.1+esm3
Available with Ubuntu Pro
-
vpx-tools
-
1.5.0-2ubuntu1.1+esm3
Available with Ubuntu Pro
Ubuntu 14.04
In general, a standard system update will make all the
necessary changes.