Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-11680

Опубликовано: 20 окт. 2025
Источник: redhat
CVSS3: 3.1
EPSS Низкий

Описание

Out-of-bounds Write in unfilter_scanline in warmcat libwebsockets allows, when the LWS_WITH_UPNG flag is enabled during compilation and the HTML display stack is used, to write past a heap allocated buffer possibly causing a crash, when the user visits an attacker controlled website that contains a crafted PNG file with a big width value that causes an integer overflow which value is used for determining the size of a heap allocation.

An out of bounds write flaw has been discovered in how libwebsockets handles PNG files. The issue is caused by the initialization of bypl struct member, whenever the multiplication of width by bypp overflows, resulting in bypl being 0, later on the buffer u->inf.out will only be allocated a buffer of size u->inf.info_size and the buffer u->u.lines will then point right after the end of the allocated buffer, thus any subsequent operation on the lines buffer will write or read past heap allocated memory.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Interconnect 1libwebsocketsFix deferred
Red Hat OpenStack Platform 16.2libwebsocketsFix deferred
Red Hat OpenStack Platform 17.1libwebsocketsFix deferred
Red Hat Service Interconnect 2libwebsocketsFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2405135libwebsockets: Out-of-bounds Write in libwebsockets PNG parsing

EPSS

Процентиль: 30%
0.00367
Низкий

3.1 Low

CVSS3

Связанные уязвимости

ubuntu
10 месяцев назад

Out-of-bounds Write in unfilter_scanline in warmcat libwebsockets allows, when the LWS_WITH_UPNG flag is enabled during compilation and the HTML display stack is used, to write past a heap allocated buffer possibly causing a crash, when the user visits an attacker controlled website that contains a crafted PNG file with a big width value that causes an integer overflow which value is used for determining the size of a heap allocation.

nvd
10 месяцев назад

Out-of-bounds Write in unfilter_scanline in warmcat libwebsockets allows, when the LWS_WITH_UPNG flag is enabled during compilation and the HTML display stack is used, to write past a heap allocated buffer possibly causing a crash, when the user visits an attacker controlled website that contains a crafted PNG file with a big width value that causes an integer overflow which value is used for determining the size of a heap allocation.

debian
10 месяцев назад

Out-of-bounds Write in unfilter_scanline in warmcat libwebsockets allo ...

github
10 месяцев назад

Out-of-bounds Write in unfilter_scanline in warmcat libwebsockets allows, when the LWS_WITH_UPNG flag is enabled during compilation and the HTML display stack is used, to write past a heap allocated buffer possibly causing a crash, when the user visits an attacker controlled website that contains a crafted PNG file with a big width value that causes an integer overflow which value is used for determining the size of a heap allocation.

EPSS

Процентиль: 30%
0.00367
Низкий

3.1 Low

CVSS3