CVE-2020-36332
published 2021-05-21CVE-2020-36332: A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from this…
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.97%
78.1th percentile
A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from this vulnerability is to the service availability.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | libwebp | < libwebp 0.6.1-2.1 (bookworm) | libwebp 0.6.1-2.1 (bookworm) |
| msrc | cm1_libwebp_1.0.3-1_on_cbl_mariner_1.0 | — | — |
| redhat | enterprise_linux | — | — |
| webmproject | libwebp | < 1.0.1 | 1.0.1 |
| webmproject | libwebp | — | — |
| webmproject | libwebp | >= 0 < 0.6.1-2.1 | 0.6.1-2.1 |
| webmproject | libwebp | >= 0 < 0.6.1-2.1 | 0.6.1-2.1 |
| webmproject | libwebp | >= 0 < 0.6.1-2.1 | 0.6.1-2.1 |
| webmproject | libwebp | >= 0 < 0.6.1-2.1 | 0.6.1-2.1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fx92-p77r-3r2c: A flaw was found in libwebp in versions before 1
ghsa_unreviewed·2022-05-24
CVE-2020-36332 [HIGH] CWE-20 GHSA-fx92-p77r-3r2c: A flaw was found in libwebp in versions before 1
A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from this vulnerability is to the service availability.
OSV
CVE-2020-36332: A flaw was found in libwebp in versions before 1
osv·2021-05-21·CVSS 7.5
CVE-2020-36332 [HIGH] CVE-2020-36332: A flaw was found in libwebp in versions before 1
A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from this vulnerability is to the service availability.
Ubuntu
libwebp vulnerabilities
vendor_ubuntu·2021-06-01
CVE-2020-36331 libwebp vulnerabilities
Title: libwebp vulnerabilities
Summary: libwebp could be made to crash or run programs as your login if it
opened a specially crafted file.
It was discovered that libwebp incorrectly handled certain malformed
images. If a user or automated system were tricked into opening a specially
crafted image file, a remote attacker could use this issue to cause libwebp
to crash, resulting in a denial of service, or possibly execute arbitrary
code.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from this vulnerability is to the service availability.
vendor_msrc·2021-05-11·CVSS 7.5
CVE-2020-36332 [HIGH] CWE-400 A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from this vulnerability is to the service availability.
A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from this vulnerability is to the service availability.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CV
Red Hat
libwebp: excessive memory allocation when reading a file
vendor_redhat·2020-02-25·CVSS 7.5
CVE-2020-36332 [HIGH] CWE-20 libwebp: excessive memory allocation when reading a file
libwebp: excessive memory allocation when reading a file
A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from this vulnerability is to the service availability.
A flaw was found in libwebp. When reading a file libwebp allocates an excessive amount of memory. The highest threat from this vulnerability is to the service availability.
Statement: This issue did not affect the versions of Firefox and Thunderbird as shipped with Red Hat Enterprise Linux 7, and 8 as they embed the fixed version of libwebp.
Package: firefox (Red Hat Enterprise Linux 7) - Out of support scope
Package: libwebp (Red Hat Enterprise Linux 7) - Out of support scope
Package: qt5-qtimageformats (Red Hat Enterprise Linux 7)
Debian
CVE-2020-36332: libwebp - A flaw was found in libwebp in versions before 1.0.1. When reading a file libweb...
vendor_debian·2020·CVSS 7.5
CVE-2020-36332 [HIGH] CVE-2020-36332: libwebp - A flaw was found in libwebp in versions before 1.0.1. When reading a file libweb...
A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from this vulnerability is to the service availability.
Scope: local
bookworm: resolved (fixed in 0.6.1-2.1)
bullseye: resolved (fixed in 0.6.1-2.1)
forky: resolved (fixed in 0.6.1-2.1)
sid: resolved (fixed in 0.6.1-2.1)
trixie: resolved (fixed in 0.6.1-2.1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1956868https://security.netapp.com/advisory/ntap-20211104-0004/https://www.debian.org/security/2021/dsa-4930https://bugzilla.redhat.com/show_bug.cgi?id=1956868https://security.netapp.com/advisory/ntap-20211104-0004/https://www.debian.org/security/2021/dsa-4930
2021-05-21
Published