There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. Calling vpx_img_wrap() with a large value of the d_w, d_h, or stride_align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. We recommend upgrading to version 1.14.1 or beyond
History

Tue, 22 Jul 2025 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Debian
Debian debian Linux
Webmproject
Webmproject libvpx
CPEs cpe:2.3:a:webmproject:libvpx:*:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
Vendors & Products Debian
Debian debian Linux
Webmproject
Webmproject libvpx
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'}


Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00277}

epss

{'score': 0.00266}


Fri, 22 Nov 2024 15:45:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:enterprise_linux:9

Wed, 28 Aug 2024 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat enterprise Linux
CPEs cpe:/a:redhat:enterprise_linux:8
Vendors & Products Redhat
Redhat enterprise Linux

cve-icon MITRE

Status: PUBLISHED

Assigner: Google

Published: 2024-06-03T13:30:26.925Z

Updated: 2025-02-13T17:54:05.905Z

Reserved: 2024-05-22T09:42:54.906Z

Link: CVE-2024-5197

cve-icon Vulnrichment

Updated: 2024-08-01T21:03:11.058Z

cve-icon NVD

Status : Analyzed

Published: 2024-06-03T14:15:09.520

Modified: 2025-07-22T18:17:56.937

Link: CVE-2024-5197

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-06-04T00:00:00Z

Links: CVE-2024-5197 - Bugzilla