Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:43739
HistoryOct 11, 2023 - 4:27 a.m.

Buffer Overflow

2023-10-1104:27:56
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6
buffer overflow
libexempi.so
webp_support.cpp
vulnerability
webp file
software

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

37.9%

libexempi.so is vulnerable to Buffer Overflow. The vulnerability exists in the VP8XChunk function of WEBP_Support.cpp, allowing an attacker to crash the application by opening a maliciously crafted webp file.

CPENameOperatorVersion
libexempi.sole3.4.5
libexempi.sole3.4.5

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

37.9%