Mageia 2019-0369: libvpx security update
Summary
Updated libvpx packages fix security vulnerabilities:
It was discovered that libvpx did not properly handle certain malformed
WebM media files. If an application using libvpx opened a specially crafted
WebM file, a remote attacker could cause a denial of service, or possibly
execute arbitrary code (CVE-2019-2126, CVE-2019-9371).
References
- https://bugs.mageia.org/show_bug.cgi?id=25789
- https://ubuntu.com/security/notices/USN-4199-1
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-2126
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9371
Resolution
MGASA-2019-0369 - Updated libvpx packages fix security vulnerabilities
SRPMS
- 7/core/libvpx-1.8.1-1.mga7