{"id":"openSUSE-SU-2021:4170-1","summary":"Security update for libaom","details":"This update for libaom fixes the following issues:\n\n- CVE-2020-36129: Fixed stack buffer overflow via the component src/aom_image.c (bsc#1193356).\n- CVE-2020-36131: Fixed stack buffer overflow via the component stats/rate_hist.c (bsc#1193365).\n- CVE-2020-36135: Fixed NULL pointer dereference via the component rate_hist.c (bsc#1193366).\n- CVE-2020-36130: Fixed NULL pointer dereference via the component av1/av1_dx_iface.c (bsc#1193369).\n","modified":"2026-03-11T07:33:22.688860Z","published":"2021-12-23T08:54:07Z","related":["CVE-2020-36129","CVE-2020-36130","CVE-2020-36131","CVE-2020-36135"],"upstream":["CVE-2020-36129","CVE-2020-36130","CVE-2020-36131","CVE-2020-36135"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/3CU5I3APCIYTJ5MCNA4TTKLC2PLKDGKU/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1193356"},{"type":"REPORT","url":"https://bugzilla.suse.com/1193365"},{"type":"REPORT","url":"https://bugzilla.suse.com/1193366"},{"type":"REPORT","url":"https://bugzilla.suse.com/1193369"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-36129"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-36130"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-36131"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-36135"}],"affected":[{"package":{"name":"libaom","ecosystem":"openSUSE:Leap 15.3","purl":"pkg:rpm/opensuse/libaom&distro=openSUSE%20Leap%2015.3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.0-3.9.1"}]}],"ecosystem_specific":{"binaries":[{"aom-tools":"1.0.0-3.9.1","libaom-devel-doc":"1.0.0-3.9.1","libaom-devel":"1.0.0-3.9.1","libaom0-32bit":"1.0.0-3.9.1","libaom0":"1.0.0-3.9.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2021:4170-1.json"}}],"schema_version":"1.7.5"}