ALAS2-2018-1015


Amazon Linux 2 Security Advisory: ALAS-2018-1015
Advisory Release Date: 2018-05-10 17:25 Pacific
Advisory Updated Date: 2018-05-11 00:01 Pacific
Severity: Low

Issue Overview:

Denial of service (DoS) in vpx/src/vpx_image.c file
A vulnerability in the Android media framework (libvpx) related to odd frame width.(CVE-2017-13194)


Affected Packages:

libvpx


Note:

This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.


Issue Correction:
Run yum update libvpx to update your system.

New Packages:
src:
    libvpx-1.3.0-5.amzn2.0.2.src

x86_64:
    libvpx-1.3.0-5.amzn2.0.2.x86_64
    libvpx-devel-1.3.0-5.amzn2.0.2.x86_64
    libvpx-utils-1.3.0-5.amzn2.0.2.x86_64
    libvpx-debuginfo-1.3.0-5.amzn2.0.2.x86_64