PT-2023-31783 · Libwebp+4 · Libwebp+4

Publicado

2023-09-12

·

Atualizado

2024-06-15

·

CVE-2023-5129

CVSS v3.1

9.6

Crítica

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions libwebp versions 0.5.0 through 1.3.1
Description A critical vulnerability has been identified in the libwebp image library, which can be exploited by a remote attacker to perform an out-of-bounds memory write via a crafted HTML page. The vulnerability is caused by a heap buffer overflow in the libwebp library, allowing attackers to execute arbitrary code on the system. The vulnerability has been given a maximum CVSS score of 10.0, indicating its high severity. It is estimated that millions of applications are affected by this vulnerability, including major web browsers and other popular software. The vulnerability has been exploited in the wild, and patches are being rolled out for affected applications.
Recommendations To resolve the issue, update libwebp to version 1.3.2 or later, which includes a patch for the "OOB write in BuildHuffmanTable" vulnerability. As a temporary workaround, consider restricting access to the vulnerable libwebp library until a patch is available. Avoid using the ReadHuffmanCodes() function and the BuildHuffmanTable() function until the issue is resolved. Additionally, be cautious when handling WebP lossless files, as they can be used to exploit the vulnerability.

Exploit

Correção

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CESA-2023_5184
CESA-2023_5201
CESA-2023_5309
CVE-2023-5129
GHSA-56PW-MPJ4-FXWW
GHSA-94VC-P8W7-5P49
GHSA-J7HP-H8JX-5PPR
OPENSUSE-SU-2024:13304-1
PYSEC-2023-174
PYSEC-2023-175
RHSA-2023:5183
RHSA-2023:5184
RHSA-2023:5185
RHSA-2023:5186
RHSA-2023:5187
RHSA-2023:5188
RHSA-2023:5189
RHSA-2023:5190
RHSA-2023:5191
RHSA-2023:5192
RHSA-2023:5197
RHSA-2023:5198
RHSA-2023:5200
RHSA-2023:5201
RHSA-2023:5202
RHSA-2023:5204
RHSA-2023:5205
RHSA-2023:5214
RHSA-2023:5223
RHSA-2023:5224
RHSA-2023:5236
RHSA-2023:5309
RHSA-2023_5184
RHSA-2023_5191
RHSA-2023_5197
RHSA-2023_5200
RHSA-2023_5201
RHSA-2023_5214
RHSA-2023_5224
RHSA-2023_5309
RLSA-2023:5201
RLSA-2023:5214
RUSTSEC-2023-0060
RUSTSEC-2023-0061

Produtos afetados

Centos
Red Hat
Red Os
Rocky Linux
Libwebp