CVE-2024-5171 is a critical integer overflow vulnerability in the libaom library's img_alloc_helper function, affecting aomedia libaom. This flaw can lead to a heap buffer overflow when large values are passed to aom_img_alloc, aom_img_wrap, or aom_img_alloc_with_border, resulting in incorrect buffer size calculations and potentially invalid aom_image_t struct fields. With a CVSS score of 9.8 (Critical), it presents a severe risk as it can be exploited remotely without user interaction, leading to high impact on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0.0, <= 3.9.0CPE matchmatch criteria | cpe:2.3:a:aomedia:libaom:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP7 Security Updates
Jun 3, 2025HP ThinPro 8.1 SP7 Security Updates
Jun 3, 2025heap buffer overflow in libaom
Jun 11, 2024libaom: Integer overflow in internal function img_alloc_helper
Jun 5, 2024