UBUNTU-CVE-2023-5217
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-5217
UBUNTU-CVE-2023-5217
Summary:
Details: Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
References: https://ubuntu.com/security/CVE-2023-5217, https://www.mozilla.org/en-US/security/advisories/mfsa2023-44/#CVE-2023-5217, https://www.openwall.com/lists/oss-security/2023/09/28/5, https://hg.mozilla.org/mozilla-central/rev/c53f5ef77b62b79af86951a7f9130e1896b695d2, https://crbug.com/1486441, https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_27.html, http://www.openwall.com/lists/oss-security/2023/09/28/5, http://www.openwall.com/lists/oss-security/2023/09/28/6, https://ubuntu.com/security/notices/USN-6403-1, https://ubuntu.com/security/notices/USN-6404-1, https://ubuntu.com/security/notices/USN-6405-1, https://ubuntu.com/security/notices/USN-6403-2, https://ubuntu.com/security/notices/USN-6403-3, https://www.cve.org/CVERecord?id=CVE-2023-5217, https://www.cisa.gov/known-exploited-vulnerabilities-catalog, https://ubuntu.com/security/notices/USN-7172-1
Affected packages
Package
Name: libvpx
Purl: pkg:deb/ubuntu/[email protected]~esm3?arch=source&distro=esm-infra-legacy/trusty
Affected ranges
Type: ECOSYSTEM
Events:
