Headline
CVE-2020-36328: heap-based buffer overflow in WebPDecode*Into functions
A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Description Guilherme de Almeida Suckevicz 2021-05-04 13:59:01 UTC
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in WebPDecode*Into functions.
Reference: https://bugs.chromium.org/p/webp/issues/detail?id=383
Comment 1 Riccardo Schirone 2021-05-13 10:38:02 UTC
Upstream patch: https://chromium.googlesource.com/webm/libwebp/+/dad31750e374eff8e02fb467eb562d4bf236ed6e
Comment 5 Riccardo Schirone 2021-05-17 10:47:48 UTC
Upstream release notes: https://chromium.googlesource.com/webm/libwebp/+/v1.0.1
Comment 10 errata-xmlrpc 2021-06-07 12:18:13 UTC
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2021:2260 https://access.redhat.com/errata/RHSA-2021:2260
Comment 11 Product Security DevOps Team 2021-06-07 15:03:56 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-36328
Comment 12 errata-xmlrpc 2021-06-08 22:38:15 UTC
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2021:2328 https://access.redhat.com/errata/RHSA-2021:2328
Comment 13 errata-xmlrpc 2021-06-09 00:25:45 UTC
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2021:2354 https://access.redhat.com/errata/RHSA-2021:2354
Comment 14 errata-xmlrpc 2021-06-09 13:32:24 UTC
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8.1 Extended Update Support
Via RHSA-2021:2365 https://access.redhat.com/errata/RHSA-2021:2365
Comment 15 errata-xmlrpc 2021-06-09 13:51:00 UTC
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8.2 Extended Update Support
Via RHSA-2021:2364 https://access.redhat.com/errata/RHSA-2021:2364