CVE-2023-44488
Published Sep 30, 2023
·Updated
Last updated 24 July 2024
Affected Software
8 affected componentsFixes available
debian/libvpx
1.9.0-1+deb11u31.12.0-1+deb12u31.15.0-2
webmproject libvpx<1.13.1
redhat Enterprise Linux=8.0
redhat Enterprise Linux=9.0
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Debian Debian Linux=12.0
Fedoraproject Fedora=37
Remediation
Patch Available
Event History
Sep 30, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Oct 2, 2023
Data Sourced
via Red Hat·08:06 PM
DescriptionSeverityAffected Software
Jan 12, 2024
Data Sourced
via Launchpad·12:25 AM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·04:16 AM
RemedyDescriptionSeverityAffected Software
Feb 23, 2025
Data Sourced
via Debian·01:59 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2023-44488?
CVE-2023-44488 is a vulnerability in VP9 in libvpx before 1.13.1 that mishandles widths, leading to a crash related to encoding.
2
How does CVE-2023-44488 affect libvpx?
CVE-2023-44488 affects libvpx versions before 1.13.1.
3
What is the severity of CVE-2023-44488?
CVE-2023-44488 has a severity level of high.
4
How do I fix the CVE-2023-44488 vulnerability?
To fix the CVE-2023-44488 vulnerability, update to libvpx version 1.13.1 or later.
5
Where can I find more information about CVE-2023-44488?
You can find more information about CVE-2023-44488 on the MITRE CVE database and the Ubuntu security notices.