This vulnerability is trending on Twitter; this may indicate a growing threat.
Snyk has a published code exploit for this vulnerability.
The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade webmproject/libwebp
to version 1.3.2 or higher.
Affected versions of this package are vulnerable to Heap-based Buffer Overflow. This advisory has been marked deprecated in favor of CVE-2023-4863
An attacker can craft a special WebP
lossless file that triggers the ReadHuffmanCodes()
function to allocate the HuffmanCode buffer with a size that comes from an array of precomputed sizes: kTableSize
. The color_cache_bits
value defines which size to use. The kTableSize
array only takes into account sizes for 8-bit first-level table lookups but not second-level table lookups. libwebp allows codes that are up to 15-bit (MAX_ALLOWED_CODE_LENGTH
). When BuildHuffmanTable()
attempts to fill the second-level tables it may write data out-of-bounds. The OOB write to the undersized array happens in ReplicateValue()
.
Notes:
This is only exploitable if the color_cache_bits
value defines which size to use.
This vulnerability was first published on Chrome as CVE-2023-4863.
Changelog:
2023-09-26: Initial advisory publication
2023-09-27: Advisory details updated, including CVSS, CWE, references
2023-09-27: CVE-2023-5129 rejected as a duplicate of CVE-2023-4863
2023-09-28: This advisory has been marked deprecated in favor of CVE-2023-4863