Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-478j-8hp8-fjpw

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. The highest threat from this vulnerability is to data confidentiality and to the service availability.

A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. The highest threat from this vulnerability is to data confidentiality and to the service availability.

EPSS

Процентиль: 38%
0.00164
Низкий

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 9.1
ubuntu
больше 4 лет назад

A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. The highest threat from this vulnerability is to data confidentiality and to the service availability.

CVSS3: 9.1
redhat
почти 6 лет назад

A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. The highest threat from this vulnerability is to data confidentiality and to the service availability.

CVSS3: 9.1
nvd
больше 4 лет назад

A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. The highest threat from this vulnerability is to data confidentiality and to the service availability.

CVSS3: 9.1
msrc
больше 4 лет назад

A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. The highest threat from this vulnerability is to data confidentiality and to the service availability.

CVSS3: 9.1
debian
больше 4 лет назад

A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds ...

EPSS

Процентиль: 38%
0.00164
Низкий

Дефекты

CWE-125