PublicDateAtUSN: 2019-09-27 19:15:00 UTC Candidate: CVE-2019-9325 PublicDate: 2019-09-27 19:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9325 https://www.openwall.com/lists/oss-security/2019/11/07/1 https://chromium-review.googlesource.com/c/webm/libvpx/+/1149604 https://ubuntu.com/security/notices/USN-4199-1 Description: In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112001302 Ubuntu-Description: Notes: amurray> Fixed in versions >= 1.8.0 leosilva> vulnerability introduced in 1.4.0 Mitigation: Bugs: Priority: low Discovered-by: Assigned-to: mdeslaur CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N [6.5 MEDIUM] Patches_libvpx: upstream: https://github.com/webmproject/libvpx/commit/0681cff1ad36b3ef8ec242f59b5a6c4234ccfb88 upstream_libvpx: released (1.8.0) precise/esm_libvpx: DNE trusty_libvpx: ignored (out of standard support) trusty/esm_libvpx: not-affected xenial_libvpx: released (1.5.0-2ubuntu1.1) esm-infra/xenial_libvpx: released (1.5.0-2ubuntu1.1) bionic_libvpx: released (1.7.0-3ubuntu0.18.04.1) disco_libvpx: released (1.7.0-3ubuntu0.19.04.1) eoan_libvpx: not-affected (1.8.1-2) focal_libvpx: not-affected (1.8.1-2) devel_libvpx: not-affected (1.8.1-2)