UBUNTU-CVE-2019-9232
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-9232
UBUNTU-CVE-2019-9232
Summary:
Details: In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-122675483
References: https://ubuntu.com/security/CVE-2019-9232, https://source.android.com/security/bulletin/android-10, https://www.openwall.com/lists/oss-security/2019/11/07/1, https://chromium-review.googlesource.com/c/webm/libvpx/+/1395793, https://ubuntu.com/security/notices/USN-4199-1, https://ubuntu.com/security/notices/USN-4199-2, https://www.cve.org/CVERecord?id=CVE-2019-9232
Affected packages
Package
Name: libvpx
Purl: pkg:deb/ubuntu/[email protected]~esm1?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
