Skip to content

Conversation

@jlaine
Copy link
Member

@jlaine jlaine commented May 16, 2025

libvpx 1.14.0 is vulnerable to CVE-2024-5197.

libxml2 2.9.13 is vulnerable to CVE-2022-2309, CVE-2023-29469, CVE-2017-5130, CVE-2023-45322, CVE-2024-25062, CVE-2022-40303, CVE-2022-40304, CVE-2023-28484, CVE-2022-29824

Fixes: #1892
Fixes: #1894

@jlaine jlaine merged commit f1070b8 into PyAV-Org:main May 16, 2025
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Security Risk: av-14.3.0 includes vulnerable libxml2 version Security Risk: av-14.3.0 includes vulnerable libvpx version (CVE-2024-5197)

1 participant