CVE-2020-36329
21.05.2021, 17:15
A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| webmproject | libwebp | 𝑥 < 1.0.1 |
| redhat | enterprise_linux | 7.0 |
| redhat | enterprise_linux | 8.0 |
| netapp | ontap_select_deploy_administration_utility | - |
| debian | debian_linux | 9.0 |
| debian | debian_linux | 10.0 |
| apple | ipados | 𝑥 < 14.7 |
| apple | iphone_os | 𝑥 < 14.7 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libwebp |
|
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libwebp-devel |
| ||||||||||||||
| libwebp5 |
| ||||||||||||||
| libwebp5-32bit |
| ||||||||||||||
| libwebp6 |
| ||||||||||||||
| libwebpdecoder2 |
| ||||||||||||||
| libwebpdemux1 |
| ||||||||||||||
| libwebpdemux2 |
| ||||||||||||||
| libwebpextras0 |
| ||||||||||||||
| libwebpmux2 |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libwebp |
| ||||||||||||||||||||||||
| libwebp-devel |
| ||||||||||||||||||||||||
| libwebp-java |
| ||||||||||||||||||||||||
| libwebp-tools |
| ||||||||||||||||||||||||
| qt5-qtimageformats |
| ||||||||||||||||||||||||
| qt5-qtimageformats-doc |
|
Common Weakness Enumeration
References