Lucene search

K
freebsdFreeBSD58A738D4-57AF-11EE-8C58-B42E991FC52E
HistorySep 12, 2023 - 12:00 a.m.

libwebp heap buffer overflow

2023-09-1200:00:00
vuxml.freebsd.org
13
heap buffer overflow
google chrome
tor browser
libwebp
out of bounds memory write
chrome cve
geckoview
firefox
severity critical
unix

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.609 Medium

EPSS

Percentile

97.8%

[email protected] reports:

Heap buffer overflow in WebP in Google Chrome prior to 116.0.5845.187
allowed a remote attacker to perform an out of bounds memory write
via a crafted HTML page. (Chromium security severity: Critical)
The Tor browser is based on Firefox and GeckoView and uses also
libwep so it is affected by this bug.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchtor-browser< 12.5.3UNKNOWN

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.609 Medium

EPSS

Percentile

97.8%