Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Configuration 6 (hide)
|
Configuration 7 (hide)
|
Configuration 8 (hide)
|
Configuration 9 (hide)
|
History
03 Feb 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://news.ycombinator.com/item?id=37478403 - Exploit, Third Party Advisory | |
References | () https://www.debian.org/security/2023/dsa-5498 - Mailing List, Third Party Advisory |
20 Dec 2024, 19:00
Type | Values Removed | Values Added |
---|---|---|
References | () https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_11.html - Vendor Advisory | |
References | () https://crbug.com/1479274 - Issue Tracking, Vendor Advisory | |
References | () https://en.bandisoft.com/honeyview/history/ - Release Notes | |
References | () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6T655QF7CQ3DYAMPFV7IECQYGDEUIVVT/ - Mailing List | |
References | () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FYYKLG6CRGEDTNRBSU26EEWAO6D6U645/ - Mailing List | |
References | () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KUQ7CTX3W372X3UY56VVNAHCH6H2F4X3/ - Mailing List | |
References | () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OZDGWWMJREPAGKWCJKSCM4WYLANSKIFX/ - Mailing List | |
References | () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PYZV7TMKF4QHZ54SFJX54BDN52VHGGCX/ - Mailing List | |
References | () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WHOLML7N2G5KCAZXFWC5IDFFHSQS5SDB/ - Mailing List | |
References | () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WTRUIS3564P7ZLM2S2IH4Y4KZ327LI4I/ - Mailing List | |
References | () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-4863 - Patch, Third Party Advisory | |
References | () https://news.ycombinator.com/item?id=37478403 - Exploit | |
References | () https://www.debian.org/security/2023/dsa-5496 - Mailing List | |
References | () https://www.debian.org/security/2023/dsa-5497 - Mailing List | |
References | () https://www.debian.org/security/2023/dsa-5498 - Mailing List | |
References | () https://www.vicarius.io/vsociety/posts/zero-day-webp-vulnerability-cve-2023-4863 - Exploit, Third Party Advisory | |
CPE | cpe:2.3:a:microsoft:webp_image_extension:1.0.62681.0:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:teams:1.6.00.26463:*:*:*:*:macos:*:* |
cpe:2.3:a:microsoft:webp_image_extension:*:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:* cpe:2.3:a:microsoft:teams:*:*:*:*:desktop:*:*:* cpe:2.3:a:microsoft:teams:*:*:*:*:*:macos:*:* cpe:2.3:a:bandisoft:honeyview:*:*:*:*:*:*:*:* |
First Time |
Bandisoft
Bandisoft honeyview |
Information
Published : 2023-09-12 15:15
Updated : 2025-03-13 16:17
NVD link : CVE-2023-4863
Mitre link : CVE-2023-4863
CVE.ORG link : CVE-2023-4863
JSON object : View
Products Affected
netapp
- active_iq_unified_manager
microsoft
- teams
- webp_image_extension
- edge_chromium
bentley
- seequent_leapfrog
debian
- debian_linux
mozilla
- thunderbird
- firefox
fedoraproject
- fedora
bandisoft
- honeyview
- chrome
webmproject
- libwebp
CWE
CWE-787
Out-of-bounds Write