Amazon Linux 2 Security Advisory: ALAS-2020-1558
Advisory Release Date: 2020-11-09 17:10 Pacific
Advisory Updated Date: 2020-11-11 17:39 Pacific
A denial of service vulnerability in libvpx in Mediaserver could enable a remote attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-30436808. (CVE-2017-0393)
In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-122675483 (CVE-2019-9232)
In libvpx, there is a possible information disclosure due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-80479354 (CVE-2019-9433)
In vp8_decode_frame of decodeframe.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure if error correction were turned on, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1Android ID: A-62458770 (CVE-2020-0034)
Affected Packages:
libvpx
Issue Correction:
Run yum update libvpx to update your system.
aarch64:
libvpx-1.3.0-8.amzn2.0.1.aarch64
libvpx-devel-1.3.0-8.amzn2.0.1.aarch64
libvpx-utils-1.3.0-8.amzn2.0.1.aarch64
libvpx-debuginfo-1.3.0-8.amzn2.0.1.aarch64
i686:
libvpx-1.3.0-8.amzn2.0.1.i686
libvpx-devel-1.3.0-8.amzn2.0.1.i686
libvpx-utils-1.3.0-8.amzn2.0.1.i686
libvpx-debuginfo-1.3.0-8.amzn2.0.1.i686
src:
libvpx-1.3.0-8.amzn2.0.1.src
x86_64:
libvpx-1.3.0-8.amzn2.0.1.x86_64
libvpx-devel-1.3.0-8.amzn2.0.1.x86_64
libvpx-utils-1.3.0-8.amzn2.0.1.x86_64
libvpx-debuginfo-1.3.0-8.amzn2.0.1.x86_64