Lucene search

K
osvGoogleOSV:RUSTSEC-2023-0060
HistorySep 12, 2023 - 12:00 p.m.

libwebp: OOB write in BuildHuffmanTable

2023-09-1212:00:00
Google
osv.dev
17
libwebp
vulnerability
remote code execution
rce
heap overflow
buildhuffmantable
update
patch

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

8.7 High

AI Score

Confidence

High

0.609 Medium

EPSS

Percentile

97.8%

Google and Mozilla have released security advisories for RCE due to heap overflow in libwebp. Google warns the vulnerability has been exploited in the wild.

libwebp needs to be updated to 1.3.2 to include a patch for “OOB write in BuildHuffmanTable”.

CPENameOperatorVersion
libwebp-sys2lt0.1.8

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

8.7 High

AI Score

Confidence

High

0.609 Medium

EPSS

Percentile

97.8%