Lucene search

K
mageiaGentoo FoundationMGASA-2023-0282
HistoryOct 03, 2023 - 1:53 p.m.

Updated libwebp packages fix a security vulnerability

2023-10-0313:53:29
Gentoo Foundation
advisories.mageia.org
18
heap buffer overflow
webp
google chrome
out of bounds
memory write
crafted html page
unix

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.609 Medium

EPSS

Percentile

97.8%

Heap buffer overflow in WebP in Google Chrome prior to 116.0.5845.187 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.

OSVersionArchitecturePackageVersionFilename
Mageia8noarchlibwebp< 1.1.0-2.2libwebp-1.1.0-2.2.mga8
Mageia9noarchlibwebp< 1.3.0-2.1libwebp-1.3.0-2.1.mga9

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.609 Medium

EPSS

Percentile

97.8%