ALAS-2018-967


Amazon Linux AMI Security Advisory: ALAS-2018-967
Advisory Release Date: 2018-03-08 22:18 Pacific
Severity: Low
References: CVE-2017-13194 

Issue Overview:

Denial of service (DoS) in vpx/src/vpx_image.c file
A vulnerability in the Android media framework (libvpx) related to odd frame width (CVE-2017-13194 )


Affected Packages:

libvpx


Issue Correction:
Run yum update libvpx to update your system.

New Packages:
i686:
    libvpx-devel-1.2.0-1.1.amzn1.i686
    libvpx-debuginfo-1.2.0-1.1.amzn1.i686
    libvpx-utils-1.2.0-1.1.amzn1.i686
    libvpx-1.2.0-1.1.amzn1.i686

src:
    libvpx-1.2.0-1.1.amzn1.src

x86_64:
    libvpx-debuginfo-1.2.0-1.1.amzn1.x86_64
    libvpx-utils-1.2.0-1.1.amzn1.x86_64
    libvpx-devel-1.2.0-1.1.amzn1.x86_64
    libvpx-1.2.0-1.1.amzn1.x86_64