Resource exhaustion in libvpx - CVE-2019-9371
Published: November 29, 2019 / Updated: December 20, 2019
Vulnerability identifier: #VU23106
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-9371
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation when processing media content in libvpx. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
libvpx
Gentoo Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Opensuse
Fedora
libvpx (Debian package)
libvpx (Alpine package)
libvpx (Red Hat package)
libvpx
Gentoo Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Opensuse
Fedora
libvpx (Debian package)
libvpx (Alpine package)
libvpx (Red Hat package)
libvpx
How to mitigate CVE-2019-9371
Install update from vendor's website.
libvpx - update to 1.8.2
libvpx (Debian package) - addressed in versions 1.6.1-3+deb9u2, 1.7.0-3+deb10u1
libvpx (Red Hat package) - update to 1.7.0-8.el8
libvpx - addressed in versions 1.8.2-1.fc30, 1.8.2-1.fc31
libvpx (Debian package) - addressed in versions 1.6.1-3+deb9u2, 1.7.0-3+deb10u1
libvpx (Red Hat package) - update to 1.7.0-8.el8
libvpx - addressed in versions 1.8.2-1.fc30, 1.8.2-1.fc31