Opened 16 months ago

Closed 16 months ago

Last modified 16 months ago

#21695 closed enhancement (fixed)

libvpx-1.15.2 (Security release)

Reported by: Bruce Dubbs Owned by: Bruce Dubbs
Priority: normal Milestone: 12.4
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (5)

comment:1 by Bruce Dubbs, 16 months ago

Owner: changed from blfs-book to Bruce Dubbs
Status: new → assigned

comment:2 by Bruce Dubbs, 16 months ago

Summary: libvpx-1.15.2 → libvpx-1.15.2 (Security release)

2025-05-28 v1.15.2 "Wigeon Duck"

  • This release fixes CVE-2025-5283 (bug webm:413411335), and is ABI compatible with the previous release.
CVE-2025-5283

Use after free in libvpx in Google Chrome prior to 137.0.7151.55 
allowed a remote attacker to potentially exploit heap corruption 
via a crafted HTML page. (Chromium security severity: Medium)

comment:3 by Bruce Dubbs, 16 months ago

Resolution: → fixed
Status: assigned → closed

Fixed at commits

f416069b38 Update to whois-5.6.2.
ea36f5f952 qlite-autoconf-3500100.
c240b7ea76 Update to libvpx-1.15.2 (Security release).

comment:4 by Joe Locash, 16 months ago

Note that even though this release is ABI compatible the the previous release it IS NOT ABI compatible with 1.15.0, which was used with 12.3. It will break some things.

comment:5 by Douglas R. Reno, 16 months ago

SA-12.3-051 issued.

Included a list of packages that will need to be rebuilt after updating (thank you Joe!)

Note: See TracTickets for help on using tickets.