PublicDateAtUSN: 2019-09-27 19:15:00 UTC Candidate: CVE-2019-9232 PublicDate: 2019-09-27 19:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9232 https://source.android.com/security/bulletin/android-10 https://www.openwall.com/lists/oss-security/2019/11/07/1 https://chromium-review.googlesource.com/c/webm/libvpx/+/1395793 https://ubuntu.com/security/notices/USN-4199-1 https://ubuntu.com/security/notices/USN-4199-2 Description: In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-122675483 Ubuntu-Description: Notes: amurray> Fixed in version >= 1.8.0 Mitigation: Bugs: Priority: low Discovered-by: Assigned-to: mdeslaur CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N [7.5 HIGH] Patches_libvpx: upstream: https://github.com/webmproject/libvpx/commit/46e17f0cb4a80b36755c84b8bf15731d3386c08f upstream_libvpx: released (1.8.0) precise/esm_libvpx: DNE trusty_libvpx: ignored (out of standard support) trusty/esm_libvpx: released (1.3.0-2ubuntu0.1~esm1) xenial_libvpx: released (1.5.0-2ubuntu1.1) esm-infra/xenial_libvpx: released (1.5.0-2ubuntu1.1) bionic_libvpx: released (1.7.0-3ubuntu0.18.04.1) disco_libvpx: released (1.7.0-3ubuntu0.19.04.1) eoan_libvpx: not-affected (1.8.1-2) focal_libvpx: not-affected (1.8.1-2) devel_libvpx: not-affected (1.8.1-2)