CVE-2024-5197
Public on 2024-06-03
Modified on 2024-06-05
Description
There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. Calling vpx_img_wrap() with a large value of the d_w, d_h, or stride_align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. We recommend upgrading to version 1.14.1 or beyond
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2 - Firefox Extra | firefox | 2024-08-21 | ALAS2FIREFOX-2024-028 | Fixed |
| Amazon Linux 1 | libvpx | No Fix Planned | ||
| Amazon Linux 2 - Core | libvpx | 2025-09-29 | ALAS2-2025-3015 | Fixed |
| Amazon Linux 2023 | libvpx | 2025-09-29 | ALAS2023-2025-1207 | Fixed |
| Amazon Linux 2 - Core | thunderbird | 2025-10-27 | ALAS2-2025-3052 | Fixed |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 5.9 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |