-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2021.4006
                          libvpx security update
                             29 November 2021

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           libvpx
Publisher:         Debian
Operating System:  Debian GNU/Linux
Impact/Access:     Access Confidential Data -- Remote/Unauthenticated
Resolution:        Patch/Upgrade
CVE Names:         CVE-2020-0034  

Reference:         ASB-2020.0051
                   ESB-2020.3382
                   ESB-2020.1809
                   ESB-2020.0846

Original Bulletin: 
   https://lists.debian.org/debian-lts-announce/2021/11/msg00024.html

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- - -------------------------------------------------------------------------
Debian LTS Advisory DLA-2829-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/                          Adrian Bunk
November 27, 2021                             https://wiki.debian.org/LTS
- - -------------------------------------------------------------------------

Package        : libvpx
Version        : 1.6.1-3+deb9u3
CVE ID         : CVE-2020-0034

An out-of-bounds buffer read on truncated key frames in vp8_decode_frame 
has been fixed in libvpx, a popular library for the VP8 and VP9 video codecs.

For Debian 9 stretch, this problem has been fixed in version
1.6.1-3+deb9u3.

We recommend that you upgrade your libvpx packages.

For the detailed security status of libvpx please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/libvpx

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
- -----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEOvp1f6xuoR0v9F3wiNJCh6LYmLEFAmGioPkACgkQiNJCh6LY
mLGdAw/9GvAA175hBpQ87186u6qe1rm62IDaixyba/LSPf14yWJznKqZzw/g8ZVp
whStu5edJUVhNYcwJf2Utc5EVNgxaBfaz4WQ4jjWKVHrKPkN9CwFLAC1M7ZL33I0
jRxOi0aihgj1IWUMgxxHdPG206Z9D/xpdxXDS2RBLQA15uMDvRM6NAo4HToivyzk
Y/jRuFxYx08lwCq5mHWpe1rA8iWTjp48z+iAe3kapui39Q3ZijNIDW6RLXMUqb6l
/1Aw/S+82oj5A0WdH43KZa9U88PmX8qs3hQOVxScvTO3nckELUI3Xj82ejrLQdyD
El+o3KmmlgsACFKmDy6+lsKFBkPKySEAU12KJ9BMZQdl2CIX3CMGdvHnOfkwTZub
j9C7ySJLGUXUeyw6DNOiAf8M/bXVE4wV8KjKZ3gfEX1nkI2+6BKtGKmwTsPXuWOe
SBVuf5wMSpQ8DwXhXTLfCuH78UkQYX+eO855eAcmDDlJt+YjuZHkBiFkNl2+LvHm
6u5V6F6r7+lkFjlYZ4EPK1mq6ELXvedxNYBUFJmWE/wioXRKRyLcAZwhTgv3Gzh+
yXhRX4gcQQkdh81IQCoD9QP9YokgIhkXYvRfFWHqkqsuvXg1le1dUsh8lqGR9xhm
xYZJ5CcNGFL3EoJhOjj05wWYOHhr/ibtNEAOXFty1rIn+Ik0P34=
=TZzB
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        https://www.auscert.org.au/bulletins/

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBYaQiaONLKJtyKPYoAQhTpA/+Mr9lmeVryN5BAyrpg1XvicNDpZNiP3aT
LIqa7oOOswGCXXdRfNqi9pLyRzYOI4cpYtG4miXmmWPqCEoEkm1iFcR8sTlwMN3X
8qdVypUzjlWp6JHCiY2XEuhEuGw6FgnSkrAnSR2jBSbtEF4bHNX+2Y0LGlQAp4ZB
ftQ18Rqf97Gd8mUDOZXIKYAAmlEyyZv0R7zMA/ygeLjO8F1SbeYoIsH7x64sH7pl
/LhQMd9eKIp00/kECKJRxduc/zUeThWX5uSc/dBq6EkJ1DpI3ggyYJyLPZRJeSVf
KPKrLK0/L7WHKz8O7q/S4eJrTCQCy+eJPU8I0oj/18hk8drsxNTclpqT/y8kv7WJ
9GfmB7QNdnryZUa0IuwEMV7E5Vm7t54LwyhT+yfXlUSG52NdseUydjXiHnDIhw66
yuqD2lvGqV1qcVwuRWSzSSPi6nxxJO0tnsk70pZb4qr1A8rZUkqCuuKe7uW/uClf
E+kYxAi6pzRLl4azuHSuF5Q7KKqBwN+F/ovMxonaDRaAVYBt0HEvpi6HDCA4gwr5
Yxr2OFkBvJqITeEX/JMcIRSkb4lf+UGomdfScKzi9Nf0OpgRM4Gi48rKAk3eip50
Rq++SqJGyx2N55v9hdGk2/+bu1h6olD0l2Vzp7EL3WkfXZIg1jyQ2uXQA9fPBj1l
MhfKgLanKNc=
=77+j
-----END PGP SIGNATURE-----