9.8

CVE-2020-36328

A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Webmproject ≫ Libwebp Version < 1.0.1
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Apple ≫ iPadOS Version 14.7
Apple ≫ iPhone OS Version 14.7
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.66% 0.837
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

http://seclists.org/fulldisclosure/2021/Jul/54
Third Party Advisory
Mailing List
https://support.apple.com/kb/HT212601
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1956829
Patch
Third Party Advisory
Release Notes
Issue Tracking
https://lists.debian.org/debian-lts-announce/2021/06/msg00005.html
Third Party Advisory
Mailing List
https://lists.debian.org/debian-lts-announce/2021/06/msg00006.html
Third Party Advisory
Mailing List
https://security.netapp.com/advisory/ntap-20211112-0001/
Third Party Advisory
https://www.debian.org/security/2021/dsa-4930
Third Party Advisory