Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2021:1830-1

Опубликовано: 02 июн. 2021
Источник: suse-cvrf

Описание

Security update for libwebp

This update for libwebp fixes the following issues:

  • CVE-2018-25010: Fixed heap-based buffer overflow in ApplyFilter() (bsc#1185685).
  • CVE-2020-36330: Fixed heap-based buffer overflow in ChunkVerifyAndAssign() (bsc#1185691).
  • CVE-2020-36332: Fixed extreme memory allocation when reading a file (bsc#1185674).
  • CVE-2020-36329: Fixed use-after-free in EmitFancyRGB() (bsc#1185652).
  • CVE-2018-25012: Fixed heap-based buffer overflow in GetLE24() (bsc#1185690).
  • CVE-2018-25013: Fixed heap-based buffer overflow in ShiftBytes() (bsc#1185654).
  • CVE-2020-36331: Fixed heap-based buffer overflow in ChunkAssignData() (bsc#1185686).
  • CVE-2018-25009: Fixed heap-based buffer overflow in GetLE16() (bsc#1185673).
  • CVE-2018-25011: Fixed fail on multiple image chunks (bsc#1186247).

Список пакетов

HPE Helion OpenStack 8
libwebp5-0.4.3-4.7.1
libwebp5-32bit-0.4.3-4.7.1
libwebpdemux1-0.4.3-4.7.1
libwebpmux1-0.4.3-4.7.1
SUSE Linux Enterprise Server 12 SP2-BCL
libwebp5-0.4.3-4.7.1
libwebp5-32bit-0.4.3-4.7.1
libwebpdemux1-0.4.3-4.7.1
SUSE Linux Enterprise Server 12 SP3-BCL
libwebp5-0.4.3-4.7.1
libwebp5-32bit-0.4.3-4.7.1
libwebpdemux1-0.4.3-4.7.1
SUSE Linux Enterprise Server 12 SP3-LTSS
libwebp5-0.4.3-4.7.1
libwebp5-32bit-0.4.3-4.7.1
libwebpdemux1-0.4.3-4.7.1
SUSE Linux Enterprise Server 12 SP4-LTSS
libwebp5-0.4.3-4.7.1
libwebp5-32bit-0.4.3-4.7.1
libwebpdemux1-0.4.3-4.7.1
SUSE Linux Enterprise Server 12 SP5
libwebp5-0.4.3-4.7.1
libwebp5-32bit-0.4.3-4.7.1
libwebpdemux1-0.4.3-4.7.1
SUSE Linux Enterprise Server for SAP Applications 12 SP3
libwebp5-0.4.3-4.7.1
libwebp5-32bit-0.4.3-4.7.1
libwebpdemux1-0.4.3-4.7.1
SUSE Linux Enterprise Server for SAP Applications 12 SP4
libwebp5-0.4.3-4.7.1
libwebp5-32bit-0.4.3-4.7.1
libwebpdemux1-0.4.3-4.7.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5
libwebp5-0.4.3-4.7.1
libwebp5-32bit-0.4.3-4.7.1
libwebpdemux1-0.4.3-4.7.1
SUSE Linux Enterprise Software Development Kit 12 SP5
libwebp-devel-0.4.3-4.7.1
libwebpdecoder1-0.4.3-4.7.1
libwebpmux1-0.4.3-4.7.1
SUSE OpenStack Cloud 7
libwebpmux1-0.4.3-4.7.1
SUSE OpenStack Cloud 8
libwebp5-0.4.3-4.7.1
libwebp5-32bit-0.4.3-4.7.1
libwebpdemux1-0.4.3-4.7.1
libwebpmux1-0.4.3-4.7.1
SUSE OpenStack Cloud 9
libwebp5-0.4.3-4.7.1
libwebp5-32bit-0.4.3-4.7.1
libwebpdemux1-0.4.3-4.7.1
libwebpmux1-0.4.3-4.7.1
SUSE OpenStack Cloud Crowbar 8
libwebp5-0.4.3-4.7.1
libwebp5-32bit-0.4.3-4.7.1
libwebpdemux1-0.4.3-4.7.1
libwebpmux1-0.4.3-4.7.1
SUSE OpenStack Cloud Crowbar 9
libwebp5-0.4.3-4.7.1
libwebp5-32bit-0.4.3-4.7.1
libwebpdemux1-0.4.3-4.7.1
libwebpmux1-0.4.3-4.7.1

Описание

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE16().


Затронутые продукты
HPE Helion OpenStack 8:libwebp5-0.4.3-4.7.1
HPE Helion OpenStack 8:libwebp5-32bit-0.4.3-4.7.1
HPE Helion OpenStack 8:libwebpdemux1-0.4.3-4.7.1
HPE Helion OpenStack 8:libwebpmux1-0.4.3-4.7.1

Ссылки

Описание

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ApplyFilter().


Затронутые продукты
HPE Helion OpenStack 8:libwebp5-0.4.3-4.7.1
HPE Helion OpenStack 8:libwebp5-32bit-0.4.3-4.7.1
HPE Helion OpenStack 8:libwebpdemux1-0.4.3-4.7.1
HPE Helion OpenStack 8:libwebpmux1-0.4.3-4.7.1

Ссылки

Описание

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in PutLE16().


Затронутые продукты
HPE Helion OpenStack 8:libwebp5-0.4.3-4.7.1
HPE Helion OpenStack 8:libwebp5-32bit-0.4.3-4.7.1
HPE Helion OpenStack 8:libwebpdemux1-0.4.3-4.7.1
HPE Helion OpenStack 8:libwebpmux1-0.4.3-4.7.1

Ссылки

Описание

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24().


Затронутые продукты
HPE Helion OpenStack 8:libwebp5-0.4.3-4.7.1
HPE Helion OpenStack 8:libwebp5-32bit-0.4.3-4.7.1
HPE Helion OpenStack 8:libwebpdemux1-0.4.3-4.7.1
HPE Helion OpenStack 8:libwebpmux1-0.4.3-4.7.1

Ссылки

Описание

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes().


Затронутые продукты
HPE Helion OpenStack 8:libwebp5-0.4.3-4.7.1
HPE Helion OpenStack 8:libwebp5-32bit-0.4.3-4.7.1
HPE Helion OpenStack 8:libwebpdemux1-0.4.3-4.7.1
HPE Helion OpenStack 8:libwebpmux1-0.4.3-4.7.1

Ссылки

Описание

A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.


Затронутые продукты
HPE Helion OpenStack 8:libwebp5-0.4.3-4.7.1
HPE Helion OpenStack 8:libwebp5-32bit-0.4.3-4.7.1
HPE Helion OpenStack 8:libwebpdemux1-0.4.3-4.7.1
HPE Helion OpenStack 8:libwebpmux1-0.4.3-4.7.1

Ссылки

Описание

A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. The highest threat from this vulnerability is to data confidentiality and to the service availability.


Затронутые продукты
HPE Helion OpenStack 8:libwebp5-0.4.3-4.7.1
HPE Helion OpenStack 8:libwebp5-32bit-0.4.3-4.7.1
HPE Helion OpenStack 8:libwebpdemux1-0.4.3-4.7.1
HPE Helion OpenStack 8:libwebpmux1-0.4.3-4.7.1

Ссылки

Описание

A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkAssignData. The highest threat from this vulnerability is to data confidentiality and to the service availability.


Затронутые продукты
HPE Helion OpenStack 8:libwebp5-0.4.3-4.7.1
HPE Helion OpenStack 8:libwebp5-32bit-0.4.3-4.7.1
HPE Helion OpenStack 8:libwebpdemux1-0.4.3-4.7.1
HPE Helion OpenStack 8:libwebpmux1-0.4.3-4.7.1

Ссылки

Описание

A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from this vulnerability is to the service availability.


Затронутые продукты
HPE Helion OpenStack 8:libwebp5-0.4.3-4.7.1
HPE Helion OpenStack 8:libwebp5-32bit-0.4.3-4.7.1
HPE Helion OpenStack 8:libwebpdemux1-0.4.3-4.7.1
HPE Helion OpenStack 8:libwebpmux1-0.4.3-4.7.1

Ссылки
Уязвимость SUSE-SU-2021:1830-1