Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2020-36328: heap-based buffer overflow in WebPDecode*Into functions

A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVE
#vulnerability#web#google#linux#red_hat

Description Guilherme de Almeida Suckevicz 2021-05-04 13:59:01 UTC

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in WebPDecode*Into functions.

Reference: https://bugs.chromium.org/p/webp/issues/detail?id=383

Comment 1 Riccardo Schirone 2021-05-13 10:38:02 UTC

Upstream patch: https://chromium.googlesource.com/webm/libwebp/+/dad31750e374eff8e02fb467eb562d4bf236ed6e

Comment 5 Riccardo Schirone 2021-05-17 10:47:48 UTC

Upstream release notes: https://chromium.googlesource.com/webm/libwebp/+/v1.0.1

Comment 10 errata-xmlrpc 2021-06-07 12:18:13 UTC

This issue has been addressed in the following products:

Red Hat Enterprise Linux 7

Via RHSA-2021:2260 https://access.redhat.com/errata/RHSA-2021:2260

Comment 11 Product Security DevOps Team 2021-06-07 15:03:56 UTC

This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2020-36328

Comment 12 errata-xmlrpc 2021-06-08 22:38:15 UTC

This issue has been addressed in the following products:

Red Hat Enterprise Linux 7

Via RHSA-2021:2328 https://access.redhat.com/errata/RHSA-2021:2328

Comment 13 errata-xmlrpc 2021-06-09 00:25:45 UTC

This issue has been addressed in the following products:

Red Hat Enterprise Linux 8

Via RHSA-2021:2354 https://access.redhat.com/errata/RHSA-2021:2354

Comment 14 errata-xmlrpc 2021-06-09 13:32:24 UTC

This issue has been addressed in the following products:

Red Hat Enterprise Linux 8.1 Extended Update Support

Via RHSA-2021:2365 https://access.redhat.com/errata/RHSA-2021:2365

Comment 15 errata-xmlrpc 2021-06-09 13:51:00 UTC

This issue has been addressed in the following products:

Red Hat Enterprise Linux 8.2 Extended Update Support

Via RHSA-2021:2364 https://access.redhat.com/errata/RHSA-2021:2364

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907