ALAS2-2020-1558


Amazon Linux 2 Security Advisory: ALAS-2020-1558
Advisory Release Date: 2020-11-09 17:10 Pacific
Advisory Updated Date: 2020-11-11 17:39 Pacific
Severity: Medium

Issue Overview:

A denial of service vulnerability in libvpx in Mediaserver could enable a remote attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-30436808. (CVE-2017-0393)

In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-122675483 (CVE-2019-9232)

In libvpx, there is a possible information disclosure due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-80479354 (CVE-2019-9433)

In vp8_decode_frame of decodeframe.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure if error correction were turned on, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1Android ID: A-62458770 (CVE-2020-0034)


Affected Packages:

libvpx


Note:

This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.


Issue Correction:
Run yum update libvpx to update your system.

New Packages:
aarch64:
    libvpx-1.3.0-8.amzn2.0.1.aarch64
    libvpx-devel-1.3.0-8.amzn2.0.1.aarch64
    libvpx-utils-1.3.0-8.amzn2.0.1.aarch64
    libvpx-debuginfo-1.3.0-8.amzn2.0.1.aarch64

i686:
    libvpx-1.3.0-8.amzn2.0.1.i686
    libvpx-devel-1.3.0-8.amzn2.0.1.i686
    libvpx-utils-1.3.0-8.amzn2.0.1.i686
    libvpx-debuginfo-1.3.0-8.amzn2.0.1.i686

src:
    libvpx-1.3.0-8.amzn2.0.1.src

x86_64:
    libvpx-1.3.0-8.amzn2.0.1.x86_64
    libvpx-devel-1.3.0-8.amzn2.0.1.x86_64
    libvpx-utils-1.3.0-8.amzn2.0.1.x86_64
    libvpx-debuginfo-1.3.0-8.amzn2.0.1.x86_64