CVE-2023-4863

HIGH8.8⚠ KEVEPSS 93.3%

libwebp: OOB write in BuildHuffmanTable

發布日:2023/9/12修改日:2024/8/7加入 CISA KEV 日:2023/9/13
也稱為:GHSA-j7hp-h8jx-5pprALPINE-CVE-2023-4863A-299477569ASB-A-299477569CGA-75hp-cxgv-82q3DEBIAN-CVE-2023-4863DLA-3568-1RUSTSEC-2023-0060RUSTSEC-2023-0061

描述

[Google](https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_11.html) and [Mozilla](https://www.mozilla.org/en-US/security/advisories/mfsa2023-40/) have released security advisories for RCE due to heap overflow in libwebp. Google warns the vulnerability has been exploited in the wild. libwebp needs to be updated to 1.3.2 to include a patch for "OOB write in BuildHuffmanTable".

受影響套件(33)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH8.8CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

參考連結(71)