In vp8_decode_frame of decodeframe.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure if error correction were turned on, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1Android ID: A-62458770
http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00048.html
Source: MITRE
Published: 2020-03-10
Updated: 2020-05-23
Type: CWE-125
Base Score: 7.8
Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N
Impact Score: 6.9
Exploitability Score: 10
Severity: HIGH
Base Score: 7.5
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Impact Score: 3.6
Exploitability Score: 3.9
Severity: HIGH
OR
ID | Name | Product | Family | Severity |
---|---|---|---|---|
142738 | Amazon Linux 2 : libvpx (ALAS-2020-1558) | Nessus | Amazon Linux Local Security Checks | high |
142235 | EulerOS 2.0 SP2 : libvpx (EulerOS-SA-2020-2364) | Nessus | Huawei Local Security Checks | high |
141685 | Scientific Linux Security Update : libvpx on SL7.x x86_64 (20201001) | Nessus | Scientific Linux Local Security Checks | high |
141617 | CentOS 7 : libvpx (CESA-2020:3876) | Nessus | CentOS Local Security Checks | high |
141257 | Oracle Linux 7 : libvpx (ELSA-2020-3876) | Nessus | Oracle Linux Local Security Checks | high |
141041 | RHEL 7 : libvpx (RHSA-2020:3876) | Nessus | Red Hat Local Security Checks | high |
140827 | EulerOS 2.0 SP3 : libvpx (EulerOS-SA-2020-2060) | Nessus | Huawei Local Security Checks | high |
138260 | SUSE SLED15 / SLES15 Security Update : libvpx (SUSE-SU-2020:1297-2) | Nessus | SuSE Local Security Checks | high |
136878 | openSUSE Security Update : libvpx (openSUSE-2020-680) | Nessus | SuSE Local Security Checks | high |
136790 | SUSE SLED15 / SLES15 Security Update : libvpx (SUSE-SU-2020:1297-1) | Nessus | SuSE Local Security Checks | high |
134352 | Debian DLA-2136-1 : libvpx security update | Nessus | Debian Local Security Checks | high |