Out-of-bounds read In github.com/chai2010/webp
Description
libwebp: OOB write in BuildHuffmanTable Heap buffer overflow in libwebp allow a remote attacker to perform an out of bounds memory write via a crafted HTML page.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
go | >=1.1.2 <1.4.0 || >=0 <0.0.0-20250406010349-76805d5a8860 || >=0.0.0 <1.1.2-0.20250406010349-76805d5a8860 | 1.4.0, 0.0.0-20250406010349-76805d5a8860, 1.1.2-0.20250406010349-76805d5a8860 | |
alpine v3.21 | =0.1.2-r0 || =0.1.2-r1 || =0.1.3-r0 || =0.1.99-r0 || =0.2.0-r0 || =0.2.1-r0 || =0.3.0-r0 || =0.3.1-r0 || =0.3.1-r1 || =0.4.0-r1 || =0.4.1-r0 || =0.4.2-r0 || =0.4.3-r0 || =0.4.4-r0 || =0.5.0-r0 || =0.5.1-r0 || =0.5.2-r0 || =0.6.0-r0 || =0.6.0-r1 || =0.6.1-r0 || =1.0.0-r0 || =1.0.1-r0 || =1.0.2-r0 || =1.0.3-r0 || =1.1.0-r0 || =1.2.0-r0 || =1.2.0-r1 || =1.2.0-r2 || =1.2.1-r0 || =1.2.2-r0 || =1.2.3-r0 || =1.2.4-r0 || =1.2.4-r1 || =1.3.0-r0 || =1.3.0-r1 || =1.3.0-r2 || =1.3.0-r3 || =1.3.1-r0 || >=0 <1.3.1-r1 | 1.3.1-r1 | |
nuget | >=0 <13.3.0 | 13.3.0 | |
alpine v3.18 | =0.1.2-r0 || =0.1.2-r1 || =0.1.3-r0 || =0.1.99-r0 || =0.2.0-r0 || =0.2.1-r0 || =0.3.0-r0 || =0.3.1-r0 || =0.3.1-r1 || =0.4.0-r1 || =0.4.1-r0 || =0.4.2-r0 || =0.4.3-r0 || =0.4.4-r0 || =0.5.0-r0 || =0.5.1-r0 || =0.5.2-r0 || =0.6.0-r0 || =0.6.0-r1 || =0.6.1-r0 || =1.0.0-r0 || =1.0.1-r0 || =1.0.2-r0 || =1.0.3-r0 || =1.1.0-r0 || =1.2.0-r0 || =1.2.0-r1 || =1.2.0-r2 || =1.2.1-r0 || =1.2.2-r0 || =1.2.3-r0 || =1.2.4-r0 || =1.2.4-r1 || =1.3.0-r0 || =1.3.0-r1 || =1.3.0-r2 || =1.3.1-r0 || >=0 <1.3.1-r1 | 1.3.1-r1 | |
debian 11 | =100.0.4896.127-1 || =100.0.4896.127-1~deb11u1 || =100.0.4896.60-1 || =100.0.4896.60-1~deb11u1 || =100.0.4896.75-1 || =100.0.4896.75-1~deb11u1 || =100.0.4896.88-1 || =100.0.4896.88-1~deb11u1 || =101.0.4951.41-1 || =101.0.4951.41-1~deb11u1 || =101.0.4951.41-2 || =101.0.4951.54-1 || =101.0.4951.64-1 || =101.0.4951.64-1~deb11u1 || =102.0.5005.115-1 || =102.0.5005.115-1~deb11u1 || =102.0.5005.61-1 || =102.0.5005.61-1~deb11u1 || =103.0.5060.114-1 || =103.0.5060.114-1~deb11u1 || =103.0.5060.134-1 || =103.0.5060.134-1~deb11u1 || =103.0.5060.53-1 || =103.0.5060.53-1~deb11u1 || =104.0.5112.101-1 || =104.0.5112.101-1~deb11u1 || =104.0.5112.79-1 || =104.0.5112.79-1~deb11u1 || =105.0.5195.102-1 || =105.0.5195.102-1~deb11u1 || =105.0.5195.125-1 || =105.0.5195.125-1~deb11u1 || =105.0.5195.52-1 || =105.0.5195.52-1~deb11u1 || =106.0.5249.103-1 || =106.0.5249.103-2 || =106.0.5249.119-1 || =106.0.5249.119-1~deb11u1 || =106.0.5249.61-1 || =106.0.5249.61-1~deb11u1 || =106.0.5249.91-1 || =106.0.5249.91-1~deb11u1 || =107.0.5304.110-1 || =107.0.5304.110-1~deb11u1 || =107.0.5304.110-2 || =107.0.5304.121-1 || =107.0.5304.121-1~deb11u1 || =107.0.5304.68-1 || =107.0.5304.68-1~deb11u1 || =107.0.5304.87-1 || =107.0.5304.87-1~deb11u1 || =108.0.5359.124-1 || =108.0.5359.124-1~deb11u1 || =108.0.5359.71-1 || =108.0.5359.71-2 || =108.0.5359.71-2~deb11u1 || =108.0.5359.94-1 || =108.0.5359.94-1~deb11u1 || =109.0.5414.119-1 || =109.0.5414.119-1~deb11u1 || =109.0.5414.74-1 || =109.0.5414.74-2 || =109.0.5414.74-2~deb11u1 || =110.0.5481.177-1 || =110.0.5481.177-1~deb11u1 || =110.0.5481.77-1 || =110.0.5481.77-1~deb11u1 || =110.0.5481.77-2 || =111.0.5563.110-1 || =111.0.5563.110-1~deb11u1 || =111.0.5563.64-1 || =111.0.5563.64-1~deb11u1 || =112.0.5615.121-1 || =112.0.5615.121-1~deb11u1 || =112.0.5615.138-1 || =112.0.5615.138-1~deb11u1 || =112.0.5615.49-1 || =112.0.5615.49-2 || =112.0.5615.49-2~deb11u1 || =112.0.5615.49-2~deb11u2 || =113.0.5672.126-1 || =113.0.5672.126-1~deb11u1 || =113.0.5672.63-1 || =113.0.5672.63-1~deb11u1 || =113.0.5672.63-2 || =114.0.5735.106-1 || =114.0.5735.106-1~deb11u1 || =114.0.5735.106-1~deb12u1 || =114.0.5735.133-1 || =114.0.5735.133-1~deb11u1 || =114.0.5735.133-1~deb12u1 || =114.0.5735.198-1 || =114.0.5735.198-1~deb11u1 || =114.0.5735.198-1~deb12u1 || =114.0.5735.90-1 || =114.0.5735.90-2 || =114.0.5735.90-2~deb11u1 || =114.0.5735.90-2~deb12u1 || =115.0.5790.102-1 || =115.0.5790.102-2 || =115.0.5790.170-1 || =115.0.5790.170-1~deb11u1 || =115.0.5790.170-1~deb12u1 || =115.0.5790.98-1 || =115.0.5790.98-1~deb11u1 || =115.0.5790.98-1~deb12u1 || =115.0.5790.98-2 || =116.0.5845.110-1 || =116.0.5845.110-1~deb11u1 || =116.0.5845.110-1~deb12u1 || =116.0.5845.110-2 || =116.0.5845.140-1 || =116.0.5845.140-1~deb11u1 || =116.0.5845.140-1~deb12u1 || =116.0.5845.180-1 || =116.0.5845.180-1~deb11u1 || =116.0.5845.180-1~deb12u1 || =116.0.5845.96-1 || =116.0.5845.96-1~deb11u1 || =116.0.5845.96-1~deb12u1 || =116.0.5845.96-2 || =117.0.5938.62-1~deb11u1 || =117.0.5938.62-1~deb12u1 || =90.0.4430.212-1 || =93.0.4577.82-1 || =97.0.4692.71-0.1 || =97.0.4692.71-0.1~deb11u1 || =97.0.4692.99-1 || =97.0.4692.99-1~deb11u1 || =97.0.4692.99-1~deb11u2 || =98.0.4758.102-1 || =98.0.4758.102-1~deb11u1 || =98.0.4758.80-1 || =98.0.4758.80-1~deb11u1 || =99.0.4818.0-0.1 || =99.0.4844.51-1 || =99.0.4844.51-1~deb11u1 || =99.0.4844.51-2 || =99.0.4844.74-1 || =99.0.4844.74-1~deb11u1 || =99.0.4844.84-1 || =99.0.4844.84-1~deb11u1 || >=0 <117.0.5938.62-1 | 117.0.5938.62-1 | |
nuget | >=2.0.0 <2.88.6 | 2.88.6 | |
pypi | >=0 <10.0.1 | 10.0.1 | |
npm | >=22.0.0 <22.3.24 || >=24.0.0 <24.8.3 || >=25.0.0 <25.8.1 || >=26.0.0 <26.2.1 || >=27.0.0-beta.1 <27.0.0-beta.2 | 22.3.24, 24.8.3, 25.8.1, 26.2.1, 27.0.0-beta.2 | |
nuget | >=0 <13.3.0 | 13.3.0 | |
nuget | >=0 <13.3.0 | 13.3.0 |
1-10 of 53
10
Aliases
References
1. https://github.com/qnighy/libwebp-sys2-rs/pull/212. https://github.com/python-pillow/Pillow/pull/73953. https://github.com/jaredforth/webp/pull/304. https://github.com/electron/electron/pull/398235. https://github.com/electron/electron/pull/398256. https://github.com/electron/electron/pull/398267. https://github.com/electron/electron/pull/398278. https://github.com/electron/electron/pull/398289. https://github.com/webmproject/libwebp/commit/902bc9190331343b2017211debcec8d2ab87e17a10. https://github.com/qnighy/libwebp-sys2-rs/commit/4560c473a76ec8bd8c650f19ddf9d7a44f719f8b11. https://github.com/jaredforth/webp/commit/9d4c56e63abecc777df71c702503c3eaabd7dcbc12. https://rustsec.org/advisories/RUSTSEC-2023-0061.html13. https://rustsec.org/advisories/RUSTSEC-2023-0060.html14. https://pillow.readthedocs.io/en/stable/releasenotes/10.0.1.html#security15. https://news.ycombinator.com/item?id=3747840316. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-486317. https://adamcaudill.com/2023/09/14/whose-cve-is-it-anyway18. https://security.netapp.com/advisory/ntap-20230929-001119. https://sethmlarson.dev/security-developer-in-residence-weekly-report-1620. https://stackdiary.com/critical-vulnerability-in-webp-codec-cve-2023-486321. https://www.bentley.com/advisories/be-2023-000122. https://www.bleepingcomputer.com/news/google/google-fixes-another-chrome-zero-day-bug-exploited-in-attacks23. https://www.debian.org/security/2023/dsa-549624. https://www.debian.org/security/2023/dsa-549725. https://www.debian.org/security/2023/dsa-549826. https://www.mozilla.org/en-US/security/advisories/mfsa2023-4027. https://www.vicarius.io/vsociety/posts/zero-day-webp-vulnerability-cve-2023-486328. https://blog.isosceles.com/the-webp-0day29. https://bugzilla.suse.com/show_bug.cgi?id=121523130. https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_11.html31. https://crbug.com/147927432. https://en.bandisoft.com/honeyview/history33. https://github.com/ImageMagick/ImageMagick/discussions/666434. https://github.com/dlemstra/Magick.NET/releases/tag/13.3.035. https://github.com/webmproject/libwebp/releases/tag/v1.3.236. https://lists.fedoraproject.org/archives/list/[email protected]/message/6T655QF7CQ3DYAMPFV7IECQYGDEUIVVT37. https://lists.fedoraproject.org/archives/list/[email protected]/message/FYYKLG6CRGEDTNRBSU26EEWAO6D6U64538. https://lists.fedoraproject.org/archives/list/[email protected]/message/KUQ7CTX3W372X3UY56VVNAHCH6H2F4X339. https://lists.fedoraproject.org/archives/list/[email protected]/message/OZDGWWMJREPAGKWCJKSCM4WYLANSKIFX40. https://lists.fedoraproject.org/archives/list/[email protected]/message/PYZV7TMKF4QHZ54SFJX54BDN52VHGGCX41. https://lists.fedoraproject.org/archives/list/[email protected]/message/WHOLML7N2G5KCAZXFWC5IDFFHSQS5SDB42. https://lists.fedoraproject.org/archives/list/[email protected]/message/WTRUIS3564P7ZLM2S2IH4Y4KZ327LI4I43. http://www.openwall.com/lists/oss-security/2023/09/21/444. http://www.openwall.com/lists/oss-security/2023/09/22/145. http://www.openwall.com/lists/oss-security/2023/09/22/346. http://www.openwall.com/lists/oss-security/2023/09/22/447. http://www.openwall.com/lists/oss-security/2023/09/22/548. http://www.openwall.com/lists/oss-security/2023/09/22/649. http://www.openwall.com/lists/oss-security/2023/09/22/750. http://www.openwall.com/lists/oss-security/2023/09/22/851. http://www.openwall.com/lists/oss-security/2023/09/26/152. http://www.openwall.com/lists/oss-security/2023/09/26/753. http://www.openwall.com/lists/oss-security/2023/09/28/154. http://www.openwall.com/lists/oss-security/2023/09/28/255. http://www.openwall.com/lists/oss-security/2023/09/28/456. https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-486357. https://github.com/mistymntncop/CVE-2023-4863
Does your application use this vulnerable software?
During the free trial, our tools assess your application, identify vulnerabilities, and provide recommendations for their remediation.