CVE-2023-4863
12.09.2023, 15:15
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)Enginsight
Vendor | Product | Version |
---|---|---|
chrome | 𝑥 < 116.0.5845.187 | |
debian | debian_linux | 10.0 |
debian | debian_linux | 11.0 |
debian | debian_linux | 12.0 |
mozilla | firefox | 𝑥 < 102.15.1 |
mozilla | firefox | 𝑥 < 117.0.1 |
mozilla | firefox | 115.1.0 ≤ 𝑥 < 115.2.1 |
mozilla | thunderbird | 𝑥 < 102.15.1 |
mozilla | thunderbird | 115.0 ≤ 𝑥 < 115.2.2 |
microsoft | edge_chromium | 𝑥 < 116.0.1938.81 |
microsoft | teams | 𝑥 < 1.6.00.26463 |
microsoft | teams | 𝑥 < 1.6.00.26474 |
microsoft | webp_image_extension | 𝑥 < 1.0.62681.0 |
webmproject | libwebp | 𝑥 < 1.3.2 |
netapp | active_iq_unified_manager | - |
bentley | seequent_leapfrog | 𝑥 < 2023.2 |
bandisoft | honeyview | 𝑥 < 5.51 |
𝑥
= Vulnerable software versions

Debian Releases
Debian Product | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
chromium |
| ||||||||||||
firefox |
| ||||||||||||
firefox-esr |
| ||||||||||||
libwebp |
| ||||||||||||
thunderbird |
|

Ubuntu Releases
Ubuntu Product | |||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
chromium-browser |
| ||||||||||||||||
firefox |
| ||||||||||||||||
libwebp |
| ||||||||||||||||
thunderbird |
|
Common Weakness Enumeration
References