9.1

CVE-2020-36331

A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkAssignData. The highest threat from this vulnerability is to data confidentiality and to the service availability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Webmproject ≫ Libwebp Version < 1.0.1
Redhat ≫ Enterprise Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Apple ≫ iPadOS Version < 14.7
Apple ≫ iPhone OS Version < 14.7
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.3% 0.811
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
NIST 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:N/A:P
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

http://seclists.org/fulldisclosure/2021/Jul/54
Third Party Advisory
Mailing List
https://support.apple.com/kb/HT212601
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2021/06/msg00005.html
Third Party Advisory
Mailing List
https://lists.debian.org/debian-lts-announce/2021/06/msg00006.html
Third Party Advisory
Mailing List
https://security.netapp.com/advisory/ntap-20211112-0001/
Third Party Advisory
https://www.debian.org/security/2021/dsa-4930
Third Party Advisory
Mailing List
https://bugzilla.redhat.com/show_bug.cgi?id=1956856
Patch
Third Party Advisory
Issue Tracking