snykiotcubedev / godot-3.3-stable

MIT License
0 stars 0 forks source link

CVE-2024-5197 (High) detected in godot3.4.2-stable, godot3.4.2-stable #71

Open mend-bolt-for-github[bot] opened 1 month ago

mend-bolt-for-github[bot] commented 1 month ago

CVE-2024-5197 - High Severity Vulnerability

Vulnerable Libraries - godot3.4.2-stable, godot3.4.2-stable

Vulnerability Details

There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. Calling vpx_img_wrap() with a large value of the d_w, d_h, or stride_align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. We recommend upgrading to version 1.14.1 or beyond

Publish Date: 2024-06-03

URL: CVE-2024-5197

CVSS 3 Score Details (7.8)

Base Score Metrics: - Exploitability Metrics: - Attack Vector: Local - Attack Complexity: Low - Privileges Required: Low - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: High - Integrity Impact: High - Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2024-06-03

Fix Resolution: v1.14.1


Step up your Open Source Security Game with Mend here