OESA-2023-1740

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2023-1740
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2023-1740.json
JSON Data
https://api.test.osv.dev/v1/vulns/OESA-2023-1740
Upstream
Published
2023-10-13T11:06:07Z
Modified
2025-08-12T05:22:40.485118Z
Summary
libvpx security update
Details

libvpx provides the VP8/VP9 SDK, which allows you to integrate your applications with the VP8 and VP9 video codecs, high quality, royalty free, open source codecs deployed on millions of computers and devices worldwide.

Security Fix(es):

VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding.(CVE-2023-44488)

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)(CVE-2023-5217)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:20.03-LTS-SP1 / libvpx

Package

Name
libvpx
Purl
pkg:rpm/openEuler/libvpx&distro=openEuler-20.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.7.0-10.oe1

Ecosystem specific

{
    "x86_64": [
        "libvpx-debugsource-1.7.0-10.oe1.x86_64.rpm",
        "libvpx-1.7.0-10.oe1.x86_64.rpm",
        "libvpx-debuginfo-1.7.0-10.oe1.x86_64.rpm",
        "libvpx-devel-1.7.0-10.oe1.x86_64.rpm"
    ],
    "aarch64": [
        "libvpx-devel-1.7.0-10.oe1.aarch64.rpm",
        "libvpx-debugsource-1.7.0-10.oe1.aarch64.rpm",
        "libvpx-debuginfo-1.7.0-10.oe1.aarch64.rpm",
        "libvpx-1.7.0-10.oe1.aarch64.rpm"
    ],
    "src": [
        "libvpx-1.7.0-10.oe1.src.rpm"
    ]
}

openEuler:20.03-LTS-SP3 / libvpx

Package

Name
libvpx
Purl
pkg:rpm/openEuler/libvpx&distro=openEuler-20.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.7.0-10.oe1

Ecosystem specific

{
    "x86_64": [
        "libvpx-devel-1.7.0-10.oe1.x86_64.rpm",
        "libvpx-1.7.0-10.oe1.x86_64.rpm",
        "libvpx-debuginfo-1.7.0-10.oe1.x86_64.rpm",
        "libvpx-debugsource-1.7.0-10.oe1.x86_64.rpm"
    ],
    "aarch64": [
        "libvpx-debuginfo-1.7.0-10.oe1.aarch64.rpm",
        "libvpx-devel-1.7.0-10.oe1.aarch64.rpm",
        "libvpx-debugsource-1.7.0-10.oe1.aarch64.rpm",
        "libvpx-1.7.0-10.oe1.aarch64.rpm"
    ],
    "src": [
        "libvpx-1.7.0-10.oe1.src.rpm"
    ]
}

openEuler:22.03-LTS / libvpx

Package

Name
libvpx
Purl
pkg:rpm/openEuler/libvpx&distro=openEuler-22.03-LTS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.7.0-10.oe2203sp2

Ecosystem specific

{
    "x86_64": [
        "libvpx-devel-1.7.0-10.oe2203.x86_64.rpm",
        "libvpx-1.7.0-10.oe2203.x86_64.rpm",
        "libvpx-debuginfo-1.7.0-10.oe2203.x86_64.rpm",
        "libvpx-debugsource-1.7.0-10.oe2203.x86_64.rpm",
        "libvpx-debuginfo-1.7.0-10.oe2203sp1.x86_64.rpm",
        "libvpx-devel-1.7.0-10.oe2203sp1.x86_64.rpm",
        "libvpx-debugsource-1.7.0-10.oe2203sp1.x86_64.rpm",
        "libvpx-1.7.0-10.oe2203sp1.x86_64.rpm",
        "libvpx-debuginfo-1.7.0-10.oe2203sp2.x86_64.rpm",
        "libvpx-devel-1.7.0-10.oe2203sp2.x86_64.rpm",
        "libvpx-debugsource-1.7.0-10.oe2203sp2.x86_64.rpm",
        "libvpx-1.7.0-10.oe2203sp2.x86_64.rpm"
    ],
    "aarch64": [
        "libvpx-1.7.0-10.oe2203.aarch64.rpm",
        "libvpx-debugsource-1.7.0-10.oe2203.aarch64.rpm",
        "libvpx-debuginfo-1.7.0-10.oe2203.aarch64.rpm",
        "libvpx-devel-1.7.0-10.oe2203.aarch64.rpm",
        "libvpx-1.7.0-10.oe2203sp1.aarch64.rpm",
        "libvpx-debugsource-1.7.0-10.oe2203sp1.aarch64.rpm",
        "libvpx-debuginfo-1.7.0-10.oe2203sp1.aarch64.rpm",
        "libvpx-devel-1.7.0-10.oe2203sp1.aarch64.rpm",
        "libvpx-devel-1.7.0-10.oe2203sp2.aarch64.rpm",
        "libvpx-debuginfo-1.7.0-10.oe2203sp2.aarch64.rpm",
        "libvpx-debugsource-1.7.0-10.oe2203sp2.aarch64.rpm",
        "libvpx-1.7.0-10.oe2203sp2.aarch64.rpm"
    ],
    "src": [
        "libvpx-1.7.0-10.oe2203.src.rpm",
        "libvpx-1.7.0-10.oe2203sp1.src.rpm",
        "libvpx-1.7.0-10.oe2203sp2.src.rpm"
    ]
}

openEuler:22.03-LTS-SP1 / libvpx

Package

Name
libvpx
Purl
pkg:rpm/openEuler/libvpx&distro=openEuler-22.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.7.0-10.oe2203sp1

Ecosystem specific

{
    "x86_64": [
        "libvpx-debuginfo-1.7.0-10.oe2203sp1.x86_64.rpm",
        "libvpx-devel-1.7.0-10.oe2203sp1.x86_64.rpm",
        "libvpx-debugsource-1.7.0-10.oe2203sp1.x86_64.rpm",
        "libvpx-1.7.0-10.oe2203sp1.x86_64.rpm"
    ],
    "aarch64": [
        "libvpx-1.7.0-10.oe2203sp1.aarch64.rpm",
        "libvpx-debugsource-1.7.0-10.oe2203sp1.aarch64.rpm",
        "libvpx-debuginfo-1.7.0-10.oe2203sp1.aarch64.rpm",
        "libvpx-devel-1.7.0-10.oe2203sp1.aarch64.rpm"
    ],
    "src": [
        "libvpx-1.7.0-10.oe2203sp1.src.rpm"
    ]
}

openEuler:22.03-LTS-SP2 / libvpx

Package

Name
libvpx
Purl
pkg:rpm/openEuler/libvpx&distro=openEuler-22.03-LTS-SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.7.0-10.oe2203sp2

Ecosystem specific

{
    "x86_64": [
        "libvpx-debuginfo-1.7.0-10.oe2203sp2.x86_64.rpm",
        "libvpx-devel-1.7.0-10.oe2203sp2.x86_64.rpm",
        "libvpx-debugsource-1.7.0-10.oe2203sp2.x86_64.rpm",
        "libvpx-1.7.0-10.oe2203sp2.x86_64.rpm"
    ],
    "aarch64": [
        "libvpx-devel-1.7.0-10.oe2203sp2.aarch64.rpm",
        "libvpx-debuginfo-1.7.0-10.oe2203sp2.aarch64.rpm",
        "libvpx-debugsource-1.7.0-10.oe2203sp2.aarch64.rpm",
        "libvpx-1.7.0-10.oe2203sp2.aarch64.rpm"
    ],
    "src": [
        "libvpx-1.7.0-10.oe2203sp2.src.rpm"
    ]
}