Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 405955 (CVE-2012-0823) - <media-libs/libvpx-1.0.0 : Denial of Service vulnerability (CVE-2012-0823)
Summary: <media-libs/libvpx-1.0.0 : Denial of Service vulnerability (CVE-2012-0823)
Status: RESOLVED FIXED
Alias: CVE-2012-0823
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B3 [noglsa]
Keywords:
Depends on: 401985
Blocks:
  Show dependency tree
 
Reported: 2012-02-26 20:13 UTC by GLSAMaker/CVETool Bot
Modified: 2013-03-13 20:41 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2012-02-26 20:13:18 UTC
CVE-2012-0823 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0823):
  VP8 Codec SDK (libvpx) before 1.0.0 "Duclair" allows remote attackers to
  cause a denial of service (application crash) via (1) unspecified "corrupt
  input" or (2) by "starting decoding from a P-frame," which triggers an
  out-of-bounds read, related to "the clamping of motion vectors in SPLITMV
  blocks".
Comment 1 Alexis Ballier gentoo-dev 2012-02-29 11:54:56 UTC
1.0.0 in tree
Comment 2 Agostino Sarubbo gentoo-dev 2012-02-29 13:02:10 UTC
Arches, please test and mark stable:
=media-libs/libvpx-1.0.0
Target KEYWORDS : "alpha amd64 ppc x86"
Comment 3 Alexis Ballier gentoo-dev 2012-02-29 13:27:11 UTC
wowowow, i would wait for firefox to be fixed first :) (bug #401985)
Comment 4 Agostino Sarubbo gentoo-dev 2012-02-29 14:24:22 UTC
amd64 stable
Comment 5 Lars Wendler (Polynomial-C) (RETIRED) gentoo-dev 2012-02-29 20:59:56 UTC
Please do not stbilize libvpx-1.0.0 before bug #401985 got fixed.
Comment 6 Jory A. Pratt gentoo-dev 2012-03-01 02:16:58 UTC
(In reply to comment #1)
> 1.0.0 in tree

Alexis I need to know why ppc/ppc64 was drop'd before I can move forward with mozilla products. I am not gonna drop support for either arch.
Comment 7 Kacper Kowalik (Xarthisius) (RETIRED) gentoo-dev 2012-03-01 09:25:01 UTC
(In reply to comment #6)
> (In reply to comment #1)
> > 1.0.0 in tree
> 
> Alexis I need to know why ppc/ppc64 was drop'd before I can move forward
> with mozilla products. I am not gonna drop support for either arch.

It compiles fine on ppc*, so are the rdeps (I've tested libav,ffmpeg). Marked ~ppc/~ppc64 and lifted 'vpx' use.mask. It can be used as stable candidate pending further testing along with bug 360427
Comment 8 Jory A. Pratt gentoo-dev 2012-03-01 13:41:24 UTC
ALL archs are fine to stabilize as far as mozilla products go, you will need to stabilize latest ebuild for tb/fx/sm/icecat at the same time to prevent brekage. Thanks
Comment 9 Tobias Klausmann (RETIRED) gentoo-dev 2012-03-03 20:18:41 UTC
Doesn't compile on alpha, see bug 406821.
Comment 10 Brent Baude (RETIRED) gentoo-dev 2012-03-10 16:57:57 UTC
ppc done
Comment 11 Thomas Kahle (RETIRED) gentoo-dev 2012-03-25 15:30:49 UTC
x86 done (as part of bug 408161)
Comment 12 Tobias Klausmann (RETIRED) gentoo-dev 2012-05-18 09:45:55 UTC
Stable on alpha.
Comment 13 Tim Sammut (RETIRED) gentoo-dev 2012-05-20 22:27:04 UTC
Thanks, folks. GLSA Vote: no.
Comment 14 Sean Amoss (RETIRED) gentoo-dev Security 2012-05-22 19:49:07 UTC
GLSA vote: not so much.

Closing noglsa.