Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-4863

Опубликовано: 11 сент. 2023
Источник: redhat
CVSS3: 9.6
EPSS Критический

Описание

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)

A heap-based buffer flaw was found in the way libwebp, a library used to process "WebP" image format data, processes certain specially formatted WebP images. An attacker could use this flaw to crash or execute remotely arbitrary code in an application such as a web browser compiled with this library.

Отчет

This security issue has been classified as having an Important security impact. Desktop users are at a high risk of exploitation of this flaw with very minimal interaction. It may compromise the confidentiality, integrity, or availability of resources. Customers using this application, which does server-side image processing by linking to the libwebp library, are also potentially impacted by this flaw and are advised to update to the fixed versions of the package.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6firefoxOut of support scope
Red Hat Enterprise Linux 7libwebpNot affected
Red Hat Enterprise Linux 7thunderbirdFixedRHSA-2023:519118.09.2023
Red Hat Enterprise Linux 7firefoxFixedRHSA-2023:519718.09.2023
Red Hat Enterprise Linux 8firefoxFixedRHSA-2023:518418.09.2023
Red Hat Enterprise Linux 8thunderbirdFixedRHSA-2023:520118.09.2023
Red Hat Enterprise Linux 8libwebpFixedRHSA-2023:530920.09.2023
Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionsfirefoxFixedRHSA-2023:518318.09.2023
Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionsthunderbirdFixedRHSA-2023:518818.09.2023
Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionslibwebpFixedRHSA-2023:523619.09.2023

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=2238431libwebp: Heap buffer overflow in WebP Codec

EPSS

Процентиль: 100%
0.93991
Критический

9.6 Critical

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 2 года назад

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)

CVSS3: 8.8
nvd
почти 2 года назад

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)

msrc
почти 2 года назад

Chromium: CVE-2023-4863 Heap buffer overflow in WebP

CVSS3: 8.8
debian
почти 2 года назад

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.1 ...

suse-cvrf
больше 1 года назад

Security update for seamonkey

EPSS

Процентиль: 100%
0.93991
Критический

9.6 Critical

CVSS3