Out-of-bounds Write

Affecting libwebp package, versions <0.6.1-2+deb10u1

Report new vulnerabilities
Do your applications use this vulnerable package? Test your applications

NVD Description

Note: Versions mentioned in the description apply to the upstream libwebp package. See Remediation section below for Debian:10 relevant versions.

A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Remediation

Upgrade Debian:10 libwebp to version 0.6.1-2+deb10u1 or higher.

References

CVSS Score

9.8
critical severity
  • Attack Vector
    Network
  • Attack Complexity
    Low
  • Privileges Required
    None
  • User Interaction
    None
  • Scope
    Unchanged
  • Confidentiality
    High
  • Integrity
    High
  • Availability
    High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE
CVE-2020-36328
CWE
CWE-787
Snyk ID
SNYK-DEBIAN10-LIBWEBP-1289573
Disclosed
21 May, 2021
Published
05 May, 2021