Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-4863

Опубликовано: 12 сент. 2023
Источник: debian
EPSS Критический

Описание

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)

Пакеты

ПакетСтатусВерсия исправленияРелизТип
chromiumfixed117.0.5938.62-1package
chromiumend-of-lifebusterpackage
firefoxfixed117.0.1-1package
firefox-esrfixed115.2.1esr-1package
thunderbirdfixed1:115.2.2-1package
libwebpfixed1.2.4-0.3package

Примечания

  • https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_11.html

  • src:chromium builds against the system libwebp library

  • Fixed by: https://chromium.googlesource.com/webm/libwebp.git/+/902bc9190331343b2017211debcec8d2ab87e17a%5E%21/

  • Followup: https://chromium.googlesource.com/webm/libwebp.git/+/95ea5226c870449522240ccff26f0b006037c520%5E%21/#F0

  • https://www.mozilla.org/en-US/security/advisories/mfsa2023-40/#CVE-2023-4863

  • https://blog.isosceles.com/the-webp-0day/

  • https://www.darknavy.org/blog/exploiting_the_libwebp_vulnerability_part_1/

  • https://www.darknavy.org/blog/exploiting_the_libwebp_vulnerability_part_2/

EPSS

Процентиль: 100%
0.93991
Критический

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 2 года назад

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)

CVSS3: 9.6
redhat
почти 2 года назад

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)

CVSS3: 8.8
nvd
почти 2 года назад

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)

msrc
почти 2 года назад

Chromium: CVE-2023-4863 Heap buffer overflow in WebP

suse-cvrf
больше 1 года назад

Security update for seamonkey

EPSS

Процентиль: 100%
0.93991
Критический