Bug 18014

Summary: libvpx new security issue CVE-2016-1621
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: Mageia Bug Squad <bugsquad>
Status: RESOLVED INVALID QA Contact: Sec team <security>
Severity: normal    
Priority: Normal    
Version: 5   
Target Milestone: ---   
Hardware: All   
OS: Linux   
URL: http://lwn.net/Vulnerabilities/680036/
Whiteboard:
Source RPM: libvpx-1.3.0-3.1.mga5.src.rpm CVE:
Status comment:

Description David Walser 2016-03-15 18:43:08 CET
A security issue fixed in Android and Chrome was really a fix in libvpx 1.4.0.  It appears to be in the libwebm part of it.  I don't think we can just update to 1.4.0 in Mageia 5, since it's binary-incompatible.  I also don't know if *all* of the fix is included within this:
https://android.googlesource.com/platform/external/libvpx/+/04839626ed859623901ebd3a5fd483982186b59d%5E!/#F1

It would be nice if we could get more information on the upstream commit(s) in libvpx that fixed this issue.
Comment 1 David Walser 2016-03-21 17:16:24 CET
Fedora has issued an advisory for this on March 20:
https://lists.fedoraproject.org/pipermail/package-announce/2016-March/179128.html

Maybe the upstream fix was in 1.5.0, because the libwebm copy wasn't in 1.3.0, which was probably added in 1.4.0.  So, this doesn't affect Mageia 5 after all.

Status: NEW => RESOLVED
Resolution: (none) => INVALID