CVE-2016-9085
published 2017-02-03CVE-2016-9085: Multiple integer overflows in libwebp allows attackers to have unspecified impact via unknown vectors.
PriorityP48low3.3CVSS 3.1
AVLACLPRLUINSUCNINAL
EPSS
0.43%
34.6th percentile
Multiple integer overflows in libwebp allows attackers to have unspecified impact via unknown vectors.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libwebp | < libwebp 0.5.1-3 (bookworm) | libwebp 0.5.1-3 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| webmproject | libwebp | <= 0.5.2 | — |
| webmproject | libwebp | >= 0 < 0.5.1-3 | 0.5.1-3 |
| webmproject | libwebp | >= 0 < 0.5.1-3 | 0.5.1-3 |
| webmproject | libwebp | >= 0 < 0.5.1-3 | 0.5.1-3 |
| webmproject | libwebp | >= 0 < 0.5.1-3 | 0.5.1-3 |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv3.3LOW
vendor_debian3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6p8m-c6x4-m899: Multiple integer overflows in libwebp allows attackers to have unspecified impact via unknown vectors
ghsa_unreviewed·2022-05-13
CVE-2016-9085 [LOW] CWE-190 GHSA-6p8m-c6x4-m899: Multiple integer overflows in libwebp allows attackers to have unspecified impact via unknown vectors
Multiple integer overflows in libwebp allows attackers to have unspecified impact via unknown vectors.
OSV
CVE-2016-9085: Multiple integer overflows in libwebp allows attackers to have unspecified impact via unknown vectors
osv·2017-02-03·CVSS 3.3
CVE-2016-9085 [LOW] CVE-2016-9085: Multiple integer overflows in libwebp allows attackers to have unspecified impact via unknown vectors
Multiple integer overflows in libwebp allows attackers to have unspecified impact via unknown vectors.
Red Hat
libwebp: Several integer overflows
vendor_redhat·2016-10-10·CVSS 3.3
CVE-2016-9085 [LOW] CWE-190 libwebp: Several integer overflows
libwebp: Several integer overflows
Multiple integer overflows in libwebp allows attackers to have unspecified impact via unknown vectors.
Package: libwebp (Red Hat Enterprise Linux 7) - Not affected
Package: libwebp (Red Hat Enterprise Linux 8) - Not affected
Package: libwebp (Red Hat OpenShift Enterprise 2) - Out of support scope
Package: libwebp-java (Red Hat OpenShift Enterprise 2) - Out of support scope
Debian
CVE-2016-9085: libwebp - Multiple integer overflows in libwebp allows attackers to have unspecified impac...
vendor_debian·2016·CVSS 3.3
CVE-2016-9085 [LOW] CVE-2016-9085: libwebp - Multiple integer overflows in libwebp allows attackers to have unspecified impac...
Multiple integer overflows in libwebp allows attackers to have unspecified impact via unknown vectors.
Scope: local
bookworm: resolved (fixed in 0.5.1-3)
bullseye: resolved (fixed in 0.5.1-3)
forky: resolved (fixed in 0.5.1-3)
sid: resolved (fixed in 0.5.1-3)
trixie: resolved (fixed in 0.5.1-3)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9085 mingw-libwebp: libwebp: Several integer overflows [epel-7]
bugzilla·2016-10-27·CVSS 3.3
CVE-2016-9085 [LOW] CVE-2016-9085 mingw-libwebp: libwebp: Several integer overflows [epel-7]
CVE-2016-9085 mingw-libwebp: libwebp: Several integer overflows [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug automatically created by: add-tracking-bugs]
Disc
Bugzilla
CVE-2016-9085 libwebp: Several integer overflows [fedora-all]
bugzilla·2016-10-27·CVSS 3.3
CVE-2016-9085 [LOW] CVE-2016-9085 libwebp: Several integer overflows [fedora-all]
CVE-2016-9085 libwebp: Several integer overflows [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While on
Bugzilla
CVE-2016-9085 libwebp: Several integer overflows
bugzilla·2016-10-27·CVSS 3.3
CVE-2016-9085 [LOW] CVE-2016-9085 libwebp: Several integer overflows
CVE-2016-9085 libwebp: Several integer overflows
Multiple integer overflows were found in libwebp library.
Upstream patch:
https://chromium.googlesource.com/webm/libwebp/+/e2affacc35f1df6cc3b1a9fa0ceff5ce2d0cce83
CVE assignment:
http://seclists.org/oss-sec/2016/q4/253
Discussion:
Created libwebp tracking bugs for this issue:
Affects: fedora-all [bug 1389340]
Affects: epel-6 [bug 1389343]
---
Created mingw-libwebp tracking bugs for this issue:
Affects: fedora-all [bug 1389341]
Affects: epel-6 [bug 1389345]
---
Flaw Summary:
libwebp includes an example program called gifdec.c which uses pointer arithmetic computations with integers. The affected routines are GIFReadFrame(), ClearRectangle(), and GIFBlendFrames(). The upstream patch uses wider size_t containers instead of integer
Bugzilla
CVE-2016-9085 mingw-libwebp: libwebp: Several integer overflows [fedora-all]
bugzilla·2016-10-27·CVSS 3.3
CVE-2016-9085 [LOW] CVE-2016-9085 mingw-libwebp: libwebp: Several integer overflows [fedora-all]
CVE-2016-9085 mingw-libwebp: libwebp: Several integer overflows [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of F
Bugzilla
CVE-2016-9085 libwebp: Several integer overflows [epel-6]
bugzilla·2016-10-27·CVSS 3.3
CVE-2016-9085 [LOW] CVE-2016-9085 libwebp: Several integer overflows [epel-6]
CVE-2016-9085 libwebp: Several integer overflows [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug automatically created by: add-tracking-bugs]
Discussion:
Use the
http://www.openwall.com/lists/oss-security/2016/10/27/3http://www.securityfocus.com/bid/93928https://bugzilla.redhat.com/show_bug.cgi?id=1389338https://chromium.googlesource.com/webm/libwebp/+/e2affacc35f1df6cc3b1a9fa0ceff5ce2d0cce83https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3Ehttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LG5Q42J7EJDKQKWTTHCO4YZMOMP74YPQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PTR2ZW67TMT7KC24RBENIF25KWUJ7VPD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SH6X3MWD5AHZC5JT4625PGFHAYLR7YW7/https://security.gentoo.org/glsa/201701-61http://www.openwall.com/lists/oss-security/2016/10/27/3http://www.securityfocus.com/bid/93928https://bugzilla.redhat.com/show_bug.cgi?id=1389338https://chromium.googlesource.com/webm/libwebp/+/e2affacc35f1df6cc3b1a9fa0ceff5ce2d0cce83https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3Ehttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LG5Q42J7EJDKQKWTTHCO4YZMOMP74YPQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PTR2ZW67TMT7KC24RBENIF25KWUJ7VPD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SH6X3MWD5AHZC5JT4625PGFHAYLR7YW7/https://security.gentoo.org/glsa/201701-61
2017-02-03
Published