Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2021:2354

Опубликовано: 08 июн. 2021
Источник: rocky
Оценка: Important

Описание

Important: libwebp security update

The libwebp packages provide a library and tools for the WebP graphics format. WebP is an image format with a lossy compression of digital photographic images. WebP consists of a codec based on the VP8 format, and a container based on the Resource Interchange File Format (RIFF). Webmasters, web developers and browser developers can use WebP to compress, archive, and distribute digital images more efficiently.

Security Fix(es):

  • libwebp: heap-based buffer overflow in PutLE16() (CVE-2018-25011)

  • libwebp: heap-based buffer overflow in WebPDecode*Into functions (CVE-2020-36328)

  • libwebp: use-after-free in EmitFancyRGB() in dec/io_dec.c (CVE-2020-36329)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
libwebpi6863.el8_4libwebp-1.0.0-3.el8_4.i686.rpm
libwebp-develx86_643.el8_4libwebp-devel-1.0.0-3.el8_4.x86_64.rpm
libwebpx86_643.el8_4libwebp-1.0.0-3.el8_4.x86_64.rpm
libwebp-develi6863.el8_4libwebp-devel-1.0.0-3.el8_4.i686.rpm

Показывать по

Связанные уязвимости

oracle-oval
больше 4 лет назад

ELSA-2021-2354: libwebp security update (IMPORTANT)

oracle-oval
больше 4 лет назад

ELSA-2021-2260: libwebp security update (IMPORTANT)

oracle-oval
больше 4 лет назад

ELSA-2021-2328: qt5-qtimageformats security update (IMPORTANT)

suse-cvrf
больше 4 лет назад

Security update for libwebp

suse-cvrf
больше 4 лет назад

Security update for libwebp