File _patchinfo of Package patchinfo.13783

<patchinfo incident="13783">
  <issue tracker="cve" id="2019-9371"/>
  <issue tracker="cve" id="2019-2126"/>
  <issue tracker="cve" id="2019-9232"/>
  <issue tracker="cve" id="2019-9325"/>
  <issue tracker="cve" id="2019-9433"/>
  <issue tracker="bnc" id="1160615">VUL-1: CVE-2019-9371: libvpx: resource exhaustion after memory leak in mkvparser.cc</issue>
  <issue tracker="bnc" id="1160614">VUL-1: CVE-2019-9433: libvpx: use-after-free in vp8_deblock() in vp8/common/postproc.c</issue>
  <issue tracker="bnc" id="1160611">VUL-0: CVE-2019-2126: libvpx: double free in ParseContentEncodingEntry() in mkvparser.cc</issue>
  <issue tracker="bnc" id="1160612">VUL-1: CVE-2019-9325: libvpx: out-of-bounds read in decoder_peek_si_internal() in vp9/vp9_dx_iface.c</issue>
  <issue tracker="bnc" id="1160613">VUL-1: CVE-2019-9232: libvpx: out of bounds read in vp8_norm table</issue>
  <packager>adrianSuSE</packager>
  <rating>important</rating>
  <category>security</category>
  <summary>Security update for libvpx</summary>
  <description>This update for libvpx fixes the following issues:

- CVE-2019-2126: Fixed a double free in ParseContentEncodingEntry() (bsc#1160611).
- CVE-2019-9325: Fixed an out-of-bounds read (bsc#1160612).
- CVE-2019-9232: Fixed an out-of-bounds memory access on fuzzed data (bsc#1160613).
- CVE-2019-9433: Fixed a use-after-free in vp8_deblock() (bsc#1160614).
- CVE-2019-9371: Fixed a resource exhaustion after memory leak (bsc#1160615).
</description>
</patchinfo>