Out-of-bounds Read

Affecting libvpx package, versions <1.3.0-3+deb8u3

Report new vulnerabilities
Do your applications use this vulnerable package? Test your applications

Overview

In vp8_decode_frame of decodeframe.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure if error correction were turned on, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1Android ID: A-62458770

References

CVSS Score

7.5
high severity
  • Attack Vector
    Network
  • Attack Complexity
    Low
  • Privileges Required
    None
  • User Interaction
    None
  • Scope
    Unchanged
  • Confidentiality
    High
  • Integrity
    None
  • Availability
    None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE
CVE-2020-0034
CWE
CWE-125
Snyk ID
SNYK-DEBIAN8-LIBVPX-559344
Disclosed
10 Mar, 2020
Published
05 Mar, 2020