libvpx 1.12.0-1ubuntu2 source package in Ubuntu

Changelog

libvpx (1.12.0-1ubuntu2) mantic; urgency=medium

  * SECURITY UPDATE: Heap buffer overflow in vp8 encoding
    - debian/patches/CVE-2023-5217-1.patch: add ConfigResizeChangeThreadCount
      to test/encode_api_test.cc.
    - debian/patches/CVE-2023-5217-2.patch: disallow thread count changes
      in test/encode_api_test.cc, vp8/encoder/onyx_if.c.
    - CVE-2023-5217
  * SECURITY UPDATE: Width mishandling in vp9 encoding
    - debian/patches/CVE-2023-44488.patch: fix bug with smaller width
      bigger size in test/resize_test.cc, vp9/common/vp9_alloccommon.c,
      vp9/encoder/vp9_encoder.c.
    - CVE-2023-44488

 -- Marc Deslauriers <email address hidden>  Mon, 02 Oct 2023 06:43:10 -0400

Upload details

Uploaded by:
Marc Deslauriers
Uploaded to:
Mantic
Original maintainer:
Ubuntu Developers
Architectures:
any all
Section:
video
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section
Mantic release main video

Downloads

File Size SHA-256 Checksum
libvpx_1.12.0.orig.tar.gz 5.2 MiB f1acc15d0fd0cb431f4bf6eac32d5e932e40ea1186fe78e074254d6d003957bb
libvpx_1.12.0-1ubuntu2.debian.tar.xz 15.2 KiB 15209ca2c1b52f24703bf1e8b97149aa3f80ad853ff58b717ce4eba516417cfa
libvpx_1.12.0-1ubuntu2.dsc 2.3 KiB b9372cd2ff434ecabda79cfd659bddf66bcc6d57d0d411aad6466ebc41a18272

View changes file

Binary packages built by this source

libvpx-dev: VP8 and VP9 video codec (development files)

 VP8 and VP9 are open video codecs, originally developed by On2 and released
 as open source by Google Inc. They are the successor of the VP3 codec,
 on which the Theora codec was based.
 .
 This package contains the development libraries, header files needed by
 programs that want to compile with libvpx.

libvpx-doc: VP8 and VP9 video codec (API documentation)

 VP8 and VP9 are open video codecs, originally developed by On2 and released
 as open source by Google Inc. They are the successor of the VP3 codec,
 on which the Theora codec was based.
 .
 This package contains the HTML documentation for the libvpx library
 in /usr/share/doc/libvpx-doc.

libvpx7: VP8 and VP9 video codec (shared library)

 VP8 and VP9 are open video codecs, originally developed by On2 and released
 as open source by Google Inc. They are the successor of the VP3 codec,
 on which the Theora codec was based.
 .
 This package contains the shared libraries.

libvpx7-dbgsym: debug symbols for libvpx7
vpx-tools: VP8 and VP9 video codec encoding/decoding tools

 VP8 and VP9 are open video codecs, originally developed by On2 and released
 as open source by Google Inc. They are the successor of the VP3 codec,
 on which the Theora codec was based.
 .
 This package contains the commandline tools vpxdec and vpxenc.

vpx-tools-dbgsym: debug symbols for vpx-tools