CVE-2023-4863
12.09.2023, 15:15
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)Enginsight
| Vendor | Product | Version |
|---|---|---|
| chrome | 𝑥 < 116.0.5845.187 | |
| debian | debian_linux | 10.0 |
| debian | debian_linux | 11.0 |
| debian | debian_linux | 12.0 |
| mozilla | firefox | 𝑥 < 102.15.1 |
| mozilla | firefox | 𝑥 < 117.0.1 |
| mozilla | firefox | 115.1.0 ≤ 𝑥 < 115.2.1 |
| mozilla | thunderbird | 𝑥 < 102.15.1 |
| mozilla | thunderbird | 115.0 ≤ 𝑥 < 115.2.2 |
| microsoft | edge_chromium | 𝑥 < 116.0.1938.81 |
| microsoft | teams | 𝑥 < 1.6.00.26463 |
| microsoft | teams | 𝑥 < 1.6.00.26474 |
| microsoft | webp_image_extension | 𝑥 < 1.0.62681.0 |
| webmproject | libwebp | 𝑥 < 1.3.2 |
| netapp | active_iq_unified_manager | - |
| bentley | seequent_leapfrog | 𝑥 < 2023.2 |
| bandisoft | honeyview | 𝑥 < 5.51 |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| chromium |
| ||||||||||||
| firefox |
| ||||||||||||
| firefox-esr |
| ||||||||||||
| libwebp |
| ||||||||||||
| thunderbird |
|
Ubuntu Releases
Ubuntu Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| chromium-browser |
| ||||||||||||||||
| firefox |
| ||||||||||||||||
| libwebp |
| ||||||||||||||||
| thunderbird |
|
Common Weakness Enumeration
References