PublicDateAtUSN: 2018-01-12 23:29:00 UTC Candidate: CVE-2017-13194 PublicDate: 2018-01-12 23:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13194 https://android.googlesource.com/platform/external/libvpx/+/55cd1dd7c8d0a3de907d22e0f12718733f4e41d9 https://source.android.com/security/bulletin/pixel/2018-01-01 https://ubuntu.com/security/notices/USN-4199-1 https://ubuntu.com/security/notices/USN-4199-2 Description: A vulnerability in the Android media framework (libvpx) related to odd frame width. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-64710201. Ubuntu-Description: Notes: leosilva> code in trusty is quite different needs to be tested with the POC leosilva> if possible. Bugs: Priority: low Discovered-by: Assigned-to: mdeslaur CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_libvpx: upstream: https://github.com/webmproject/libvpx/commit/5a40c8fde11bf82cccb5bd2f57c46ab5e6262cbf upstream: https://github.com/webmproject/libvpx/commit/33c598990bc771d7367fe6282bd445e92cd856a6 upstream_libvpx: released (1.3.0-3+deb8u1, 1.7.0-2) precise/esm_libvpx: DNE trusty_libvpx: ignored (reached end-of-life) trusty/esm_libvpx: released (1.3.0-2ubuntu0.1~esm1) xenial_libvpx: released (1.5.0-2ubuntu1.1) esm-infra/xenial_libvpx: released (1.5.0-2ubuntu1.1) zesty_libvpx: ignored (reached end-of-life) artful_libvpx: ignored (reached end-of-life) bionic_libvpx: not-affected (1.7.0-3) cosmic_libvpx: not-affected (1.7.0-3) disco_libvpx: not-affected (1.7.0-3) eoan_libvpx: not-affected (1.7.0-3) focal_libvpx: not-affected (1.7.0-3) devel_libvpx: not-affected (1.7.0-3)