UBUNTU-CVE-2023-4863
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-4863
UBUNTU-CVE-2023-4863
Summary:
Details: Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
References: https://ubuntu.com/security/CVE-2023-4863, https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_11.html, https://chromium.googlesource.com/webm/libwebp.git/+/902bc9190331343b2017211debcec8d2ab87e17a, https://www.mozilla.org/en-US/security/advisories/mfsa2023-40/, https://ubuntu.com/security/notices/USN-6367-1, https://ubuntu.com/security/notices/USN-6368-1, https://ubuntu.com/security/notices/USN-6369-1, https://blog.isosceles.com/the-webp-0day/, https://ubuntu.com/security/notices/USN-6369-2, https://www.cve.org/CVERecord?id=CVE-2023-4863, https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Affected packages
Package
Name: libwebp
Purl: pkg:deb/ubuntu/[email protected]+esm1?arch=source&distro=esm-infra/bionic
Affected ranges
Type: ECOSYSTEM
Events:
