CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2024-5197

MEDIUM
5.9
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2024-06-03
Last Modified2026-06-17
Data SourcesNVD

Vulnerability Description

There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. Calling vpx_img_wrap() with a large value of the d_w, d_h, or stride_align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. We recommend upgrading to version 1.14.1 or beyond

Affected Platforms (CPE)

📦
Webmproject

Libvpx

< 1.14.1
💻
Debian

Debian Linux

= 10.0

References & Advisories

相關漏洞威脅