PT-2023-1010 · Mozilla+11 · Firefox+13
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 116.0.5845.187
libwebp versions prior to 1.3.2
Firefox versions prior to 117.0.1+build2-0ubuntu0.20.04.1
Description
A heap-based buffer overflow exists in the libwebp library used for encoding and decoding WebP images. This issue occurs during image decoding when a maliciously crafted WebP image or HTML page causes an out-of-bounds memory write. This can lead to a denial of service, application crashes, or the execution of arbitrary code by a remote attacker. The library is integrated into millions of applications, including container images for Wordpress, Nginx, and Python, which have seen over 5 billion downloads. There are reports of this issue being exploited by Pegasus in an Apple framework for reading and writing images.
Recommendations
Update to version 116.0.5845.187 or later.
Update to version 1.3.2 or later.
Update to version 117.0.1+build2-0ubuntu0.20.04.1 or later.
Exploit
Fix
RCE
DoS
Memory Corruption
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Google Chrome
Linuxmint
Firefox
Thunderbird
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Libwebp