Oval Definition:oval:com.redhat.rhsa:def:20100999
Revision Date:2010-12-20Version:637
Title:RHSA-2010:0999: libvpx security update (Moderate)
Description:The libvpx packages provide the VP8 SDK, which allows the encoding and decoding of the VP8 video codec, commonly used with the WebM multimedia container file format.

  • An integer overflow flaw, leading to arbitrary memory writes, was found in libvpx. An attacker could create a specially-crafted video encoded using the VP8 codec that, when played by a victim with an application using libvpx (such as Totem), would cause the application to crash or, potentially, execute arbitrary code. (CVE-2010-4203)

    All users of libvpx are advised to upgrade to these updated packages, which contain a backported patch to correct this issue. After installing the update, all applications using libvpx must be restarted for the changes to take effect.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2010-4203
    CVE-2010-4203
    RHSA-2010:0999
    RHSA-2010:0999-01
    RHSA-2010:0999-01
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • libvpx is earlier than 0:0.9.0-8.el6_0
  • AND libvpx is signed with Red Hat redhatrelease2 key
  • libvpx-devel is earlier than 0:0.9.0-8.el6_0
  • AND libvpx-devel is signed with Red Hat redhatrelease2 key
  • libvpx-utils is earlier than 0:0.9.0-8.el6_0
  • AND libvpx-utils is signed with Red Hat redhatrelease2 key
  • BACK