File _patchinfo of Package patchinfo.34567
<patchinfo incident="34567">
<issue tracker="bnc" id="1225879">VUL-0: CVE-2024-5197: libvpx: interger overflow when calling vpx_img_alloc() or vpx_img_wrap() with large parameters</issue>
<issue tracker="bnc" id="1216879">VUL-0: CVE-2023-44488: MozillaFirefox,MozillaThunderbird,libvpx: Re: Heap buffer overflow in vp8 encoding in libvpx</issue>
<issue tracker="bnc" id="1225403">VUL-0: CVE-2023-6349: libvpx: heap overflow when encoding a frame that has larger dimensions than the originally configured size</issue>
<issue tracker="cve" id="2023-6349"/>
<issue tracker="cve" id="2024-5197"/>
<issue tracker="cve" id="2023-44488"/>
<packager>adrianSuSE</packager>
<rating>important</rating>
<category>security</category>
<summary>Security update for libvpx</summary>
<description>This update for libvpx fixes the following issues:
- CVE-2024-5197: Fixed interger overflow when calling vpx_img_alloc() or vpx_img_wrap() with large parameters (bsc#1225879).
- CVE-2023-6349: Fixed heap overflow when encoding a frame that has larger dimensions than the originally configured size (bsc#1225403).
- CVE-2023-44488: Fixed heap buffer overflow in vp8 encoding (bsc#1216879).
</description>
</patchinfo>