Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2020-36329: use-after-free in EmitFancyRGB() in dec/io_dec.c

A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVE
#vulnerability#web#google#linux#red_hat

Description Guilherme de Almeida Suckevicz 2021-05-04 14:18:22 UTC

An use-after-free was found in libwebp in versions before 1.0.1 in EmitFancyRGB() in dec/io_dec.c.

Reference: https://bugs.chromium.org/p/webp/issues/detail?id=385

Comment 1 Riccardo Schirone 2021-05-13 10:55:14 UTC

Upstream patch: https://chromium.googlesource.com/webm/libwebp/+/569001f19fc81fcb5ab358f587a54c62e7c4665c

Comment 4 Riccardo Schirone 2021-05-17 10:47:46 UTC

Upstream release notes: https://chromium.googlesource.com/webm/libwebp/+/v1.0.1

Comment 9 errata-xmlrpc 2021-06-07 12:18:12 UTC

This issue has been addressed in the following products:

Red Hat Enterprise Linux 7

Via RHSA-2021:2260 https://access.redhat.com/errata/RHSA-2021:2260

Comment 10 Product Security DevOps Team 2021-06-07 15:04:00 UTC

This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2020-36329

Comment 11 errata-xmlrpc 2021-06-08 22:38:17 UTC

This issue has been addressed in the following products:

Red Hat Enterprise Linux 7

Via RHSA-2021:2328 https://access.redhat.com/errata/RHSA-2021:2328

Comment 12 errata-xmlrpc 2021-06-09 00:25:45 UTC

This issue has been addressed in the following products:

Red Hat Enterprise Linux 8

Via RHSA-2021:2354 https://access.redhat.com/errata/RHSA-2021:2354

Comment 13 errata-xmlrpc 2021-06-09 13:32:25 UTC

This issue has been addressed in the following products:

Red Hat Enterprise Linux 8.1 Extended Update Support

Via RHSA-2021:2365 https://access.redhat.com/errata/RHSA-2021:2365

Comment 14 errata-xmlrpc 2021-06-09 13:51:01 UTC

This issue has been addressed in the following products:

Red Hat Enterprise Linux 8.2 Extended Update Support

Via RHSA-2021:2364 https://access.redhat.com/errata/RHSA-2021:2364

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907