Amazon Linux 2 Security Advisory: ALAS-2018-1015
Advisory Release Date: 2018-05-10 17:25 Pacific
Advisory Updated Date: 2018-05-11 00:01 Pacific
Denial of service (DoS) in vpx/src/vpx_image.c file
A vulnerability in the Android media framework (libvpx) related to odd frame width.(CVE-2017-13194)
Affected Packages:
libvpx
Note:
This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.
Issue Correction:
Run yum update libvpx to update your system.
src:
libvpx-1.3.0-5.amzn2.0.2.src
x86_64:
libvpx-1.3.0-5.amzn2.0.2.x86_64
libvpx-devel-1.3.0-5.amzn2.0.2.x86_64
libvpx-utils-1.3.0-5.amzn2.0.2.x86_64
libvpx-debuginfo-1.3.0-5.amzn2.0.2.x86_64