CVE-2024-5197 - CVE House
Back to Database
Status published Medium CVE-2024-5197

Integer overflow in libvpx

Vulnerability Description

There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. Calling vpx_img_wrap() with a large value of the d_w, d_h, or stride_align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. We recommend upgrading to version 1.14.1 or beyond

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-5197

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

libvpx
Vulnerable Versions:
0

Timeline

Official Publish: June 3rd, 2024
Last Modified: February 13th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)