Severity
9.8CRITICALNVD
EPSS
0.5%
top 32.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 21
Latest updateApr 10

Description

A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages6 packages

NVDwebmproject/libwebp< 1.0.1
Debianwebmproject/libwebp< 0.6.1-2.1+3
CVEListV5webmproject/libwebplibwebp 1.0.1
NVDapple/ipados14.7
NVDapple/iphone_os14.7

Also affects: Debian Linux 10.0, 9.0, Enterprise Linux 7.0, 8.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-jxwm-333p-5cwx: A flaw was found in libwebp in versions before 12022-05-24
CVEList
CVE-2020-36328: A flaw was found in libwebp in versions before 12021-05-21
OSV
CVE-2020-36328: A flaw was found in libwebp in versions before 12021-05-21

📋Vendor Advisories

7
Palo Alto
PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS2024-04-10
Ubuntu
libwebp vulnerabilities2021-06-10
Ubuntu
libwebp vulnerabilities2021-06-01
Microsoft
A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulne2021-05-11
Red Hat
libwebp: heap-based buffer overflow in WebPDecode*Into functions2020-02-25

🕵️Threat Intelligence

2
Qualys
iOS and iPadOS 14.7 and 14.7.1 Security Update: Discover Vulnerabilities and Take Remote Response Action Using VMDR for Mobile Devices | Qualys2021-07-28
Qualys
iOS and iPadOS 14.7 and 14.7.1 Security Update: Discover Vulnerabilities and Take Remote Response Action Using VMDR for Mobile Devices2021-07-28
CVE-2020-36328 — Out-of-bounds Write in Libwebp | cvebase