PublicDateAtUSN: 2019-09-27 19:15:00 UTC Candidate: CVE-2019-9433 PublicDate: 2019-09-27 19:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9433 https://source.android.com/security/bulletin/android-10 https://www.openwall.com/lists/oss-security/2019/11/07/1 https://chromium-review.googlesource.com/c/webm/libvpx/+/1070753 https://ubuntu.com/security/notices/USN-4199-1 https://ubuntu.com/security/notices/USN-4199-2 Description: In libvpx, there is a possible information disclosure due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-80479354 Ubuntu-Description: Notes: amurray> fixed in revisions >= 1.8.0 Mitigation: Bugs: Priority: low Discovered-by: Assigned-to: mdeslaur CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N [6.5 MEDIUM] Patches_libvpx: upstream: https://github.com/webmproject/libvpx/commit/52add5896661d186dec284ed646a4b33b607d2c7 upstream_libvpx: needs-triage precise/esm_libvpx: DNE trusty_libvpx: ignored (out of standard support) trusty/esm_libvpx: released (1.3.0-2ubuntu0.1~esm1) xenial_libvpx: released (1.5.0-2ubuntu1.1) esm-infra/xenial_libvpx: released (1.5.0-2ubuntu1.1) bionic_libvpx: released (1.7.0-3ubuntu0.18.04.1) disco_libvpx: released (1.7.0-3ubuntu0.19.04.1) eoan_libvpx: not-affected (1.8.1-2) focal_libvpx: not-affected (1.8.1-2) devel_libvpx: not-affected (1.8.1-2)