Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-5129

Опубликовано: 25 сент. 2023
Источник: redhat
CVSS3: 0

Описание

This CVE ID has been rejected by its CVE Numbering Authority. Duplicate of CVE-2023-4863.

Отчет

This flaw was found to be a duplicate of CVE-2023-4863. Please see https://access.redhat.com/security/cve/CVE-2023-4863 for information about affected products and security errata.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6firefoxOut of support scope
Red Hat Enterprise Linux 7libwebpNot affected
Red Hat Enterprise Linux 9firefox:flatpak/firefoxAffected
Red Hat Enterprise Linux 9thunderbird:flatpak/thunderbirdAffected
Red Hat Enterprise Linux 7thunderbirdFixedRHSA-2023:519118.09.2023
Red Hat Enterprise Linux 7firefoxFixedRHSA-2023:519718.09.2023
Red Hat Enterprise Linux 8firefoxFixedRHSA-2023:518418.09.2023
Red Hat Enterprise Linux 8thunderbirdFixedRHSA-2023:520118.09.2023
Red Hat Enterprise Linux 8libwebpFixedRHSA-2023:530920.09.2023
Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionsfirefoxFixedRHSA-2023:518318.09.2023

Показывать по

Дополнительная информация

Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=2240759libwebp: out-of-bounds write with a specially crafted WebP lossless file

0 Low

CVSS3

Связанные уязвимости

nvd
больше 1 года назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Duplicate of CVE-2023-4863.

CVSS3: 8.8
redos
около 1 года назад

Уязвимость libwebp

CVSS3: 10
github
больше 1 года назад

With a specially crafted WebP lossless file, libwebp may write data out of bounds to the heap. The ReadHuffmanCodes() function allocates the HuffmanCode buffer with a size that comes from an array of precomputed sizes: kTableSize. The color_cache_bits value defines which size to use. The kTableSize array only takes into account sizes for 8-bit first-level table lookups but not second-level table lookups. libwebp allows codes that are up to 15-bit (MAX_ALLOWED_CODE_LENGTH). When BuildHuffmanTable() attempts to fill the second-level tables it may write data out-of-bounds. The OOB write to the undersized array happens in ReplicateValue.

rocky
больше 1 года назад

Important: libwebp security update

rocky
больше 1 года назад

Important: thunderbird security update

0 Low

CVSS3