Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Request to Update OpenSSL and libvpx Versions in Android Chime SDK Due to Identified Security Vulnerabilities #639

Open
nik910 opened this issue Nov 24, 2024 · 0 comments

Comments

@nik910
Copy link

nik910 commented Nov 24, 2024

Describe the bug
Our security team has identified two critical vulnerabilities in the current versions of OpenSSL and libvpx included in the Android Chime SDK:

libvpx (CVE-2023-44488):

Issue: VP9 in libvpx before version 1.13.1 mishandles widths, leading to a crash related to encoding.
Current Version Used (in SDK): 1.12.0
Recommended Version: 1.13.1 or higher

OpenSSL (CVE-2023-2650):

Issue: Processing some specially crafted ASN.1 object identifiers or data containing them may result in significantly slow performance.
Current Version Used (in SDK): 1.1.1s
Recommended Version: OpenSSL 3.1.1 or higher
Could you confirm the versions of these dependencies in the latest release of the Android Chime SDK? If the reported versions are still used, we request that you update them to mitigate the identified security risks.

These vulnerabilities impact the security and performance of our application, and an update would ensure compliance with modern security standards. Please let us know if there are any timelines for addressing this issue or if further information is required.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant