Gentoo Linux Security Advisory 201101-3 - Timothy B. Terriberry discovered that libvpx contains an integer overflow vulnerability in the processing of video streams that may allow user-assisted execution of arbitrary code. libvpx is vulnerable to an integer overflow vulnerability when processing crafted VP8 video streams. Versions less than 0.9.5 are affected.
1f9166d143ff2e1994d25b0bbe320ba2d22275a89c86595817c6570b27382e87
Ubuntu Security Notice 1015-1 - Christoph Diehl discovered that libvpx did not properly perform bounds checking. If an application using libvpx opened a specially crafted WebM file, an attacker could cause a denial of service or possibly execute code as the user invoking the program.
3d7f3698fdd765644a29b164662bfb4cf37221e935597d1b1ca3cd7f365c3935